Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

32844 risultati

VulnerabilitàAlta
CVE-2026-26035 - Fortinet FortiWeb Improper Authentication Vulnerability

CVE ID :CVE-2026-26035 Published : Aug. 12, 2026, 12:19 p.m. | 14 minutes ago Description :An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE7h fa
VulnerabilitàAlta
CVE-2026-70467 - Fortinet FortiSIEM Server-Side Request Forgery Vulnerability

CVE ID :CVE-2026-70467 Published : Aug. 12, 2026, 1:17 p.m. | 1 hour, 16 minutes ago Description :A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions may allow attacker to execute unauthorized code or commands via Severity: 3.8 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE7h fa
VulnerabilitàAlta
CVE-2026-71407 - Fortinet FortiOS Stack-based Buffer Overflow

CVE ID :CVE-2026-71407 Published : Aug. 12, 2026, 1:17 p.m. | 1 hour, 16 minutes ago Description :A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled. Severity: 5.6 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE7h fa
VulnerabilitàAlta
CVE-2026-70466 - Fortinet FortiWeb Improper Access Control

CVE ID :CVE-2026-70466 Published : Aug. 12, 2026, 12:19 p.m. | 14 minutes ago Description :A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to improper access control via Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE7h fa
VulnerabilitàAlta
CVE-2026-71408 - Fortinet FortiOS Resource Exhaustion Denial of Service Vulnerability

CVE ID :CVE-2026-71408 Published : Aug. 12, 2026, 1:17 p.m. | 1 hour, 16 minutes ago Description :A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service via Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE7h fa
VulnerabilitàAlta
CVE-2026-18044 - Estatik Real Estate Plugin < 4.3.4 - Unauthenticated Arbitrary-Recipient Mail Relay via Signed-Value Mismatch

CVE ID :CVE-2026-18044 Published : Aug. 12, 2026, 12:17 p.m. | 15 minutes ago Description :The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later uses to address the message sent by its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To on sites where the form is configured to route to a custom address. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE7h fa
VulnerabilitàAlta
CVE-2026-17008 - Quick PayPal Payments <= 5.7.50 - Unauthenticated Payment Bypass via PayPal IPN

CVE ID :CVE-2026-17008 Published : Aug. 12, 2026, 12:17 p.m. | 15 minutes ago Description :The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status in its PayPal IPN handler and marks an order paid on an order-token match alone, so a buyer who pays an arbitrary small amount can have a full-price order marked paid. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE7h fa
VulnerabilitàAlta
CVE-2026-16747 - Kirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email Actions

CVE ID :CVE-2026-16747 Published : Aug. 12, 2026, 12:17 p.m. | 15 minutes ago Description :The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes attacker-controlled input through shortcode execution, allowing unauthenticated users to run any shortcode registered on the site, which on a default install leads to disclosure of the site administrator's email address and an arbitrary-recipient mail relay from the victim's domain. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE7h fa
VulnerabilitàAlta
CVE-2026-16990 - Payment Button for PayPal <= 1.2.3.44 - Unauthenticated Payment Price Manipulation

CVE ID :CVE-2026-16990 Published : Aug. 12, 2026, 12:17 p.m. | 15 minutes ago Description :The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side and trusts a client-supplied payment amount, allowing unauthenticated attackers to create a real PayPal order against the merchant for an arbitrary lower amount. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE7h fa
VulnerabilitàAlta
CVE-2026-15045 - Wallet System for WooCommerce < 2.7.10 - Customer+ Checkout Price Manipulation via Unvalidated Wallet Amount

CVE ID :CVE-2026-15045 Published : Aug. 12, 2026, 12:17 p.m. | 15 minutes ago Description :The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against the customer's actual stored balance during checkout, allowing authenticated customers to arbitrarily reduce their own order total, including down to zero, and complete checkout without paying the merchant. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE7h fa
VulnerabilitàAlta
CVE-2026-16621 - Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via PayPal Advanced Return Handler

CVE ID :CVE-2026-16621 Published : Aug. 12, 2026, 12:17 p.m. | 15 minutes ago Description :The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an order in its PayPal return handler: it reads attacker-controlled parameters, performs no amount comparison and no order-ownership check, and completes the order even when the server-side gateway verification fails, allowing an unauthenticated attacker to mark arbitrary orders as paid without paying. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE7h fa
VulnerabilitàAlta
CVE-2026-15213 - Welcart e-Commerce < 2.11.33 - Unauthenticated Payment Bypass via Forged Settlement Callback

CVE ID :CVE-2026-15213 Published : Aug. 12, 2026, 12:17 p.m. | 15 minutes ago Description :The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-transfer settlement callback: an unauthenticated request can flip an order from unpaid to settled purely from an order number and a status flag, with no signature, amount, or origin check. Because these are pay-later methods, an attacker can mark their own unpaid order as settled and obtain fulfilment without paying. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE7h fa

Pagina 9 di 2737

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.