Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

33517 risultati

VulnerabilitàAlta
CVE-2026-72561 - Peppermint Lab Peppermint - Broken Access Control

CVE ID :CVE-2026-72561 Published : Aug. 11, 2026, 12:17 p.m. | 13 minutes ago Description :A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-administrative user to reconfigure the platform global OIDC/SSO settings via an unprotected configuration endpoint. The endpoint performs no administrative role check before applying new OIDC issuer settings. An attacker can redirect all SSO logins to an attacker-controlled identity provider, enabling credential harvesting for all platform users. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE3g fa
VulnerabilitàAlta
CVE-2026-72558 - CiviCRM CiviCRM - SQL Injection

CVE ID :CVE-2026-72558 Published : Aug. 11, 2026, 12:17 p.m. | 13 minutes ago Description :An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the contact search RLIKE clause. The clause concatenates a user-supplied value into the SQL query without sanitization. An attacker with staff-level access can exfiltrate all database contents including donor and member records. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE3g fa
VulnerabilitàAlta
CVE-2026-72559 - Daniel Brendel HortusFox - Cross-Site Scripting

CVE ID :CVE-2026-72559 Published : Aug. 11, 2026, 12:17 p.m. | 13 minutes ago Description :A stored cross-site scripting vulnerability in HortusFox 5.9 allows authenticated workspace members to inject persistent JavaScript into plant notes via Parsedown rendered without safe mode. Notes are rendered unescaped in the browser of every user who views the affected plant. An attacker can use this to steal session cookies or perform actions in the context of other users including administrators. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE3g fa
VulnerabilitàAlta
CVE-2026-72560 - HumanSignal Label Studio - Server-Side Request Forgery

CVE ID :CVE-2026-72560 Published : Aug. 11, 2026, 12:17 p.m. | 13 minutes ago Description :A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTION_ENABLED is set to false by default. The import-from-URL endpoint fetches any caller-supplied URL including internal loopback addresses on the default installation. An authenticated user can use this to reach internal services, cloud metadata endpoints, and other resources not intended for external access. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE3g fa
VulnerabilitàAlta
CVE-2026-72557 - Cockpit CMS Cockpit CMS - Unrestricted File Upload

CVE ID :CVE-2026-72557 Published : Aug. 11, 2026, 12:17 p.m. | 13 minutes ago Description :An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extension including PHP scripts via the asset upload endpoint. The allowed_uploads configuration defaults to wildcard (*) and uploaded files are stored in a web-accessible directory. An attacker with any authenticated account can upload a PHP webshell and execute arbitrary OS commands on the server. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE3g fa
VulnerabilitàAlta
CVE-2026-72556 - ZoneMinder ZoneMinder - Remote Code Execution

CVE ID :CVE-2026-72556 Published : Aug. 11, 2026, 12:17 p.m. | 13 minutes ago Description :A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands by exploiting a broken permission check in the Filter class. The canEdit() and canDelete() methods invoke nonexistent methods on the ZM\User class, causing PHP __call() to return a truthy value that bypasses the permission check for all users. Any authenticated user can trigger filter-based OS command execution regardless of their assigned role. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE3g fa
VulnerabilitàAlta
CVE-2026-72555 - Peppermint Lab Peppermint - Broken Access Control

CVE ID :CVE-2026-72555 Published : Aug. 11, 2026, 12:17 p.m. | 13 minutes ago Description :A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.roles_active flag defaults to false, causing all permission checks on ticket, client, and user handlers to behave as no-ops on default installations. All authenticated users bypass ownership and administrative access controls. An attacker with any user account can read, modify, or delete tickets, clients, and users belonging to any other account. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE3g fa
VulnerabilitàAlta
CVE-2026-50237 (CVSS 7.4)

A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined with catalog metadata poisoning and admin-mediated chart installation, this enables privilege escalation.

NVD (NIST)3g fa
VulnerabilitàAlta
CVE-2026-50236 (CVSS 7.4)

An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.

NVD (NIST)3g fa
News
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices A malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics un ... Read more Published Date: Aug 11, 2026 (1 day, 19 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom3g fa
VulnerabilitàCritica
CVE-2026-58231 (CVSS 10)

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

NVD (NIST)4g fa
News
Gunra Ransomware Builds a New Attack Network Through RaaS

Gunra Ransomware Builds a New Attack Network Through RaaS Gunra ransomware has expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program, prompting the FBI, CISA and other agencies to issue a joint advisory warning organiz ... Read more Published Date: Aug 11, 2026 (1 day, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-24472 CVE-2024-55591

CVEfeed Newsroom4g fa

Pagina 95 di 2794

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.