EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
OpenCTI · conoscenza correlata

Intelligence correlata

Entità descrittive correlate da OpenCTI e materializzate nel portale. Il flusso è unidirezionale: OpenCTI invia a Intel soltanto metadati pubblici minimizzati.

Entità disponibili73631metadati materializzati
Tipologie5Catalogo pubblico
Ultima ricezione26/09/2026 15:05operativo
ClassificazioneTLP:CLEARo fonte OSINT pubblica verificata
Vittimologia correlata

Paesi bersaglio dei gruppi

Relazioni intrusion set → paese, periodo selezionato
United States of America qilin, Wallstreet, Global Secret Group128
Germany lockbit5, thegentlemen, qilin41
United Kingdom of Great Britain and Northern Ireland chaos, thegentlemen, qilin38
Italy qilin, lockbit5, spacebears37
Canada qilin, settra, safepay35
Brazil emperador, qilin, lockbit532
India krybit, thegentlemen, Global Secret Group28
France qilin, medusalocker, krybit26
Argentina thegentlemen, dragonforce, lockbit521
Australia thegentlemen, qilin, kairos21
Mexico qilin, krybit, thegentlemen20
Spain qilin, safepay, thegentlemen20
Vista materializzata

Conoscenza disponibile

200 risultati mostrati
TipologiaEntitàFonteCondivisioneAggiornata
Vulnerabilità CVE-2026-100313A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file updatequer... The CVE Program PUBLIC-OSINT 26/09/2026 14:14 Apri scheda
Vulnerabilità CVE-2026-84095The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one of its AJAX handlers, and the nonce protecting it is generated for every visi... The CVE Program PUBLIC-OSINT 26/09/2026 14:14 Apri scheda
Vulnerabilità CVE-2026-96526The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one of its workflow REST routes, allowing users with the Contr... The CVE Program PUBLIC-OSINT 26/09/2026 14:14 Apri scheda
Vulnerabilità CVE-2026-96525The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or sufficient capability check on its workflow create, update and delete REST routes, al... The CVE Program PUBLIC-OSINT 26/09/2026 14:14 Apri scheda
Vulnerabilità CVE-2026-85081The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin ... The CVE Program PUBLIC-OSINT 26/09/2026 14:14 Apri scheda
Vulnerabilità CVE-2026-89237The Bluff Post WordPress plugin through 1.1.1 does not sanitise and escape parameters before using them as identifiers in a SQL query, allowing unauthenticated attackers to appe... The CVE Program PUBLIC-OSINT 26/09/2026 14:14 Apri scheda
Vulnerabilità CVE-2026-100314A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the fil... The CVE Program PUBLIC-OSINT 26/09/2026 14:14 Apri scheda
Vulnerabilità CVE-2026-94367OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup. An authenticated administrator can supply crafted backu... The CVE Program PUBLIC-OSINT 26/09/2026 14:14 Apri scheda
Vulnerabilità CVE-2026-100311A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The affected element is an unknown function of the file... The CVE Program PUBLIC-OSINT 26/09/2026 14:14 Apri scheda
Vulnerabilità CVE-2026-96524The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker ... The CVE Program PUBLIC-OSINT 26/09/2026 14:14 Apri scheda
Vulnerabilità CVE-2026-11871The Team Members WordPress plugin through 9.2 does not perform any authorization or visibility check in an unauthenticated AJAX action that returns full team member records by I... The CVE Program PUBLIC-OSINT 26/09/2026 14:14 Apri scheda
Vulnerabilità CVE-2026-96533The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, allowing u... The CVE Program PUBLIC-OSINT 26/09/2026 14:14 Apri scheda
Vulnerabilità CVE-2026-18143The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup... The CVE Program PUBLIC-OSINT 26/09/2026 14:14 Apri scheda
Vulnerabilità CVE-2026-96531The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper element, allowing us... The CVE Program PUBLIC-OSINT 26/09/2026 14:14 Apri scheda
Vulnerabilità CVE-2026-100312A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the... The CVE Program PUBLIC-OSINT 26/09/2026 14:14 Apri scheda
Vulnerabilità CVE-2026-84097The wp-review-slider-pro WordPress plugin before 12.7.12 does not sanitize a value stored through one of its AJAX handlers, which lacks a capability check, before using it in a ... The CVE Program PUBLIC-OSINT 26/09/2026 14:14 Apri scheda
Vulnerabilità CVE-2026-16591The WP Directory Kit WordPress plugin before 1.5.8 does not sanitize and escape some of its category and location fields before outputting them in page attributes, allowing user... The CVE Program PUBLIC-OSINT 26/09/2026 14:14 Apri scheda
Vulnerabilità CVE-2026-84096The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on the AJAX handler that saves its review submission forms, and the nonce protecting... The CVE Program PUBLIC-OSINT 26/09/2026 14:14 Apri scheda
Vulnerabilità CVE-2026-96532The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthe... The CVE Program PUBLIC-OSINT 26/09/2026 14:14 Apri scheda
Vulnerabilità CVE-2026-92411The WP Delicious WordPress plugin before 1.10.8 does not validate or escape the HTML tag name taken from user-supplied recipe block data before rendering it on the front end, al... The CVE Program PUBLIC-OSINT 26/09/2026 14:14 Apri scheda
Vulnerabilità CVE-2026-98163In the Linux kernel, the following vulnerability has been resolved: cgroup: Avoid iteration of dying tasks with zero refcount The commit 260fbcb92bbea ("cgroup: Move dying_tasks... The CVE Program PUBLIC-OSINT 26/09/2026 14:14 Apri scheda
Vulnerabilità CVE-2026-19708The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under a fixed ... The CVE Program PUBLIC-OSINT 26/09/2026 14:14 Apri scheda
Report lockbit5 has published a new victim: taspenlife.comTaspen Life offers a range of insurance products including health protection, group protection, and... Ransomware.Live TLP:CLEAR 26/09/2026 10:28 Apri scheda
Report lockbit5 has published a new victim: anery.com.brSomos a Anery Home Care Temos paixão por cuidar Nossa especialidade é cuidar de pessoas, com todo o... Ransomware.Live TLP:CLEAR 26/09/2026 10:28 Apri scheda
Report lockbit5 has published a new victim: corisricambi.itPresenti sul territorio da oltre un ventennio, la CO.R.I.S. S.r.l. è cresciuta all'interno del... Ransomware.Live TLP:CLEAR 26/09/2026 10:28 Apri scheda
Report incransom has published a new victim: pharma5.maPharma5 21, Rue des Asphodèles, Maârif Extension, 20100 Casablanca, Morocco 05 22 23 62 15 pharma5.ma Leaked data: 50Gb Corporate and financial information, data on products and... Ransomware.Live TLP:CLEAR 26/09/2026 10:28 Apri scheda
Report qilin has published a new victim: Iberia Compositech ManufacturingN/A Ransomware.Live TLP:CLEAR 26/09/2026 10:27 Apri scheda
Report Vexy Ransomware has published a new victim: Majani Insurance BrokersMajani Insurance Brokers is an independent insurance broker serving both businesses and individuals. It arranges insurance products across areas including general business insur... Ransomware.Live TLP:CLEAR 26/09/2026 10:27 Apri scheda
Report everest has published a new victim: ETS[AI generated] N/A "ETS" is too generic an identifier to reliably describe—there are numerous distinct organizations using this name or acronym across different industries and c... Ransomware.Live TLP:CLEAR 26/09/2026 10:27 Apri scheda
Report everest has published a new victim: CENELEC[AI generated] CENELEC (European Committee for Electrotechnical Standardization) is a Brussels, Belgium-based standardization organization operating across Europe. It develops v... Ransomware.Live TLP:CLEAR 26/09/2026 10:27 Apri scheda
Report everest has published a new victim: UNIRITA[AI generated] UNIRITA Inc. is a Japanese IT company headquartered in Tokyo, Japan, operating in the information technology and systems software industry. It specializes in IT o... Ransomware.Live TLP:CLEAR 26/09/2026 10:27 Apri scheda
Report everest has published a new victim: Reliance Audit[AI generated] N/A I don't have verified, reliable information about a specific company named "Reliance Audit." This name is generic and could refer to multiple small firms or l... Ransomware.Live TLP:CLEAR 26/09/2026 10:27 Apri scheda
Report Wallstreet has published a new victim: Breast Implant Center of HawaiiBreast Implant Center of Hawaii is a plastic surgery and aesthetics clinic serving patients across Hawaii. Based in Kailua-Kona, it offers breast augmentation, implant revision,... Ransomware.Live TLP:CLEAR 26/09/2026 10:27 Apri scheda
Report Wallstreet has published a new victim: Tobin & CompanyTobin & Company, CPA’s is a small accounting firm based in Harrison, New York, providing accounting, tax, auditing, and business consulting services, with a particular focus on ... Ransomware.Live TLP:CLEAR 26/09/2026 10:27 Apri scheda
Report Wallstreet has published a new victim: Ar Valve ResourcesAR Valve Resources is a UK-based distributor of industrial valves, actuators, regulators, instrumentation, and spare parts. Based in Kent, the company serves national and intern... Ransomware.Live TLP:CLEAR 26/09/2026 10:27 Apri scheda
Report Wallstreet has published a new victim: GTFMGTFM LLC is a company operating through gtfmllc.com. Its website currently provides limited publicly accessible information, so its specific products or services could not be confirmed. Ransomware.Live TLP:CLEAR 26/09/2026 10:27 Apri scheda
Report everest has published a new victim: Morula IVF[AI generated] Morula IVF is a network of fertility clinics operating in Indonesia, specializing in in vitro fertilization (IVF) and other assisted reproductive technologies. It... Ransomware.Live TLP:CLEAR 26/09/2026 10:27 Apri scheda
Report Wallstreet has published a new victim: Beatus CartonsBeatus Cartons is a UK-based, privately owned manufacturer of printed folding cartons and packaging. Established in 1940, it produces solidboard, litho-laminated, and plastic pa... Ransomware.Live TLP:CLEAR 26/09/2026 10:27 Apri scheda
Report emperador has published a new victim: Electrolux & OntracHello Electrolux & OnTrac, Still no response from you. When we called your IT helpdesk posing as threat researchers and asked about the breach, we were told, "We cannot talk abo... Ransomware.Live TLP:CLEAR 26/09/2026 10:27 Apri scheda
Report everest has published a new victim: Securitas Group[AI generated] Securitas Group is a Swedish multinational security services company headquartered in Stockholm, Sweden. It operates in the security industry, providing guarding ... Ransomware.Live TLP:CLEAR 26/09/2026 10:27 Apri scheda
Report metaencryptor has published a new victim: Platinum Healthcare StaffingPlatinum Healthcare Staffing is a healthcare staffing agency headquartered in Lafayette, USA, founded in 2005. It provides nursing and allied healthcare professionals, including... Ransomware.Live TLP:CLEAR 26/09/2026 10:27 Apri scheda
Report metaencryptor has published a new victim: PKF HadiwinataPKF Hadiwinata is a top-10 accounting and professional services firm in Indonesia, headquartered in the financial district of Jakarta. Founded in 1987, it is a member of PKF Int... Ransomware.Live TLP:CLEAR 26/09/2026 10:27 Apri scheda
Report metaencryptor has published a new victim: GE Vernova Inc.GE Vernova Inc. is a global energy equipment manufacturing and services company headquartered in Cambridge, Massachusetts. Formed from General Electric's energy businesses, it o... Ransomware.Live TLP:CLEAR 26/09/2026 10:27 Apri scheda
Report SilentRansomGroup has published a new victim: S...Redacted entry - full company name pending disclosure (FULL DATA TIMER active). Ransomware.Live TLP:CLEAR 26/09/2026 10:26 Apri scheda
Report SilentRansomGroup has published a new victim: N...Redacted entry - full company name pending disclosure (FULL DATA TIMER active). Ransomware.Live TLP:CLEAR 26/09/2026 10:26 Apri scheda
Vulnerabilità CVE-2026-100581OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the device Keychain. Attackers with access to unencrypted dev... The CVE Program PUBLIC-OSINT 26/09/2026 08:16 Apri scheda
Vulnerabilità CVE-2026-100523Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain validation. Unauthenticated attackers can ... The CVE Program PUBLIC-OSINT 26/09/2026 08:15 Apri scheda
Vulnerabilità CVE-2026-15273The Automatic.css plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI in all version 4.0.0 due to insufficient input sanitization and output escapi... The CVE Program PUBLIC-OSINT 26/09/2026 08:15 Apri scheda
Vulnerabilità CVE-2026-100540OpenClaw Feishu before 2026.8.1 fails to validate whether a configured default account is disabled before selecting it for model tool operations. Attackers can exploit multi-acc... The CVE Program PUBLIC-OSINT 26/09/2026 08:15 Apri scheda
Vulnerabilità CVE-2026-100536OpenClaw versions before 2026.8.1 fail to validate all source fields in structured message attachments, allowing attackers to hide unvalidated host paths behind allowed attachme... The CVE Program PUBLIC-OSINT 26/09/2026 08:15 Apri scheda
Vulnerabilità CVE-2026-100525The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prometheus) before version 2026.9.3 does not enforce the operator.read scope on its authenticated metrics endpo... The CVE Program PUBLIC-OSINT 26/09/2026 08:15 Apri scheda
Vulnerabilità CVE-2026-100529OpenClaw versions before 2026.8.1 contain an authorization scope widening vulnerability in file-transfer allow-always approvals that allows attackers to reuse standing grants fo... The CVE Program PUBLIC-OSINT 26/09/2026 08:15 Apri scheda
Vulnerabilità CVE-2026-100594OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the /export-trajectory endpoint that allows non-owner senders to request and receive owner-onl... The CVE Program PUBLIC-OSINT 26/09/2026 08:15 Apri scheda
Vulnerabilità CVE-2026-100570OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the CLOUDSDK_PYTHON_ARGS environment variable. When an opera... The CVE Program PUBLIC-OSINT 26/09/2026 08:15 Apri scheda
Vulnerabilità CVE-2026-100503Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter function caused by stale INDIRECT effect-op references. At... The CVE Program PUBLIC-OSINT 26/09/2026 08:15 Apri scheda
Vulnerabilità CVE-2026-100534OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions. An attacker ... The CVE Program PUBLIC-OSINT 26/09/2026 08:15 Apri scheda
Vulnerabilità CVE-2026-100586OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create... The CVE Program PUBLIC-OSINT 26/09/2026 08:15 Apri scheda
Vulnerabilità CVE-2026-100563OpenClaw (npm package `openclaw`) before 2026.8.1 does not neutralize leading characters that spreadsheet applications interpret as formulas when the Control UI exports session ... The CVE Program PUBLIC-OSINT 26/09/2026 08:15 Apri scheda
Vulnerabilità CVE-2026-100578OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the chat.send endpoint. In Gateway deployments using authenti... The CVE Program PUBLIC-OSINT 26/09/2026 08:15 Apri scheda
Vulnerabilità CVE-2026-100584OpenClaw is an npm-distributed agent runtime. In versions >= 2026.2.26 and < 2026.7.1, PowerShell command analysis on Windows hosts running in exec allowlist mode could approve ... The CVE Program PUBLIC-OSINT 26/09/2026 08:15 Apri scheda
Vulnerabilità CVE-2026-96258A vulnerability has been found in onSite internet GmbH Auktion NG Auktionssoftware up to 20260722. This affects an unknown part of the file /forgotpasswd.html of the component P... The CVE Program PUBLIC-OSINT 26/09/2026 08:15 Apri scheda
Vulnerabilità CVE-2026-100572OpenClaw versions >= 2026.3.25 and < 2026.8.1 apply invalid-token rate limiting for Synology Chat webhooks before authentication and key the limit on the raw proxy socket addres... The CVE Program PUBLIC-OSINT 26/09/2026 08:15 Apri scheda
Vulnerabilità CVE-2026-100556OpenClaw (npm package openclaw) versions >= 2026.5.2 and command to reset the shared group session and persist a provider and model override. This allows a command-denied group ... The CVE Program PUBLIC-OSINT 26/09/2026 08:15 Apri scheda
Vulnerabilità CVE-2026-100571OpenClaw (npm package 'openclaw') versions >= 2026.6.6 and < 2026.8.1 apply the SMS webhook invalid-request rate limit before Twilio signature verification and identify clients ... The CVE Program PUBLIC-OSINT 26/09/2026 08:15 Apri scheda
Vulnerabilità CVE-2026-100597OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror filesystem mutation operations. The remov... The CVE Program PUBLIC-OSINT 26/09/2026 08:15 Apri scheda
Vulnerabilità CVE-2026-100590OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner external-channel senders to persist Gateway voice configu... The CVE Program PUBLIC-OSINT 26/09/2026 08:15 Apri scheda
Vulnerabilità CVE-2026-100558OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauthenticated clients to retain response sockets by sending W... The CVE Program PUBLIC-OSINT 26/09/2026 08:15 Apri scheda
Vulnerabilità CVE-2026-100554OpenClaw (npm package 'openclaw') versions >= 2026.5.12 and < 2026.8.1 do not immediately invalidate Canvas HTTP authorization when a paired node is revoked. Node revocation inv... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-100532@openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the o... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-100587OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation command. Non-owner channel senders can install arbitrary p... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-100592OpenClaw is an agent gateway distributed via npm. In versions >= 2026.4.10 and < 2026.7.1, persistent memory dreaming mutations omit owner permission checks. An authorized but n... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-100599OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The googlemeet.chrome command accepts caller-supplied a... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-100591OpenClaw is an npm-distributed agent gateway. In versions before 2026.7.1, the global Active Memory toggle mutations could omit owner checks. An authorized non-owner external-ch... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-100504Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 function when processing negative shift amounts from p-co... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-100595OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the diagnostics export command that allows non-owner channel senders to access owner-only host... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-100577OpenClaw versions before 2026.8.1 fail to validate video asset URLs returned by providers, allowing server-side requests to private destinations. A malicious or compromised prov... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-100527OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending-authentication ... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-95924A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_f... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-100560OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. A... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-100583OpenClaw Discord versions before 2026.7.1 contain an authorization bypass vulnerability in guild metadata read actions that allows lower-trust senders to retrieve information ex... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-100574OpenClaw (npm package 'openclaw') before 2026.8.1 contains a server-side request forgery vulnerability in its trusted-host DNS checks. For fetches that use the trusted-host DNS ... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-100585OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code permission prompts delivered through the MCP channel ... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-100549OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in QQBot voice attachment handling where filenames are decoded twice, allowing encoded traversal segment... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-100588OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, alth... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-95657A vulnerability was determined in dgtlmoon Changedetection.io up to 0.55.8. This issue affects the function setCurrentSelectedText of the file changedetectionio/static/js/visual... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-100539OpenClaw (npm package 'openclaw') before 2026.8.1 fails to revoke memory tool access when an operator hot-disables memory configuration. Existing memory_search and memory_get to... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-100559OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers ca... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-100543OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-100546OpenClaw (npm package `openclaw`) versions >= 2026.7.2 and < 2026.9.2 contain a race condition in the Discord realtime voice transcript path. Concurrent control-classified voice... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-100593OpenClaw (npm package `openclaw`) before 2026.7.1 does not enforce the documented owner-only requirement for persistent `/activation` policy changes in group channels. An author... The CVE Program PUBLIC-OSINT 26/09/2026 08:14 Apri scheda
Vulnerabilità CVE-2026-100569OpenClaw is an npm-distributed application. In versions >= 2026.4.25 and < 2026.8.1, the workspace environment-variable filter did not block variables ending in `_ENDPOINT`, so ... The CVE Program PUBLIC-OSINT 26/09/2026 08:13 Apri scheda
Vulnerabilità CVE-2026-100553OpenClaw versions >= 2026.6.9 and < 2026.8.1 do not declare the native chatId parameter as a delivery target in the Feishu unpin feature, so unpin requests can bypass the shared... The CVE Program PUBLIC-OSINT 26/09/2026 08:13 Apri scheda
Vulnerabilità CVE-2026-100505Ghidra versions 11.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when decoding multi-byte UTF-8, UTF-16, or UTF-32 characters w... The CVE Program PUBLIC-OSINT 26/09/2026 08:13 Apri scheda
Vulnerabilità CVE-2026-100538OpenClaw (npm package 'openclaw') before 2026.8.1 does not apply the originating sender's global or per-agent toolsBySender policy when handling outbound attachments. A sender t... The CVE Program PUBLIC-OSINT 26/09/2026 08:13 Apri scheda
Vulnerabilità CVE-2026-100535OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is per... The CVE Program PUBLIC-OSINT 26/09/2026 08:13 Apri scheda
Vulnerabilità CVE-2026-6103phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide and holds values up to 0x1FFFFFFFF, so a ... The CVE Program PUBLIC-OSINT 26/09/2026 05:34 Apri scheda
Vulnerabilità CVE-2026-100381Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - UploadWizard Extension allows Cross... The CVE Program PUBLIC-OSINT 26/09/2026 05:32 Apri scheda
Vulnerabilità CVE-2026-81963Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. The CVE Program TLP:CLEAR 26/09/2026 05:32 Apri scheda
Vulnerabilità CVE-2026-67279RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a sess... The CVE Program TLP:CLEAR 26/09/2026 05:31 Apri scheda
Vulnerabilità CVE-2026-100379Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App allows Accessing/Intercepting/Modifying HTTP Cookies. This... The CVE Program PUBLIC-OSINT 26/09/2026 05:28 Apri scheda
Vulnerabilità CVE-2026-97884A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatestuden... The CVE Program PUBLIC-OSINT 26/09/2026 05:27 Apri scheda
Vulnerabilità CVE-2026-53628GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding the Update auth and sync or Update auth, sync and 2FA right... The CVE Program PUBLIC-OSINT 26/09/2026 05:22 Apri scheda
Vulnerabilità CVE-2026-53625GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through the API to change another use... The CVE Program PUBLIC-OSINT 26/09/2026 05:22 Apri scheda
Vulnerabilità CVE-2026-45801GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user without the required permission can enable debug mode. The aff... The CVE Program PUBLIC-OSINT 26/09/2026 05:20 Apri scheda
Vulnerabilità CVE-2026-97896A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationForm::rules of the file packages/Webkul/Admin/src/Http/Req... The CVE Program PUBLIC-OSINT 26/09/2026 05:20 Apri scheda
Vulnerabilità CVE-2026-88832BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images. The CVE Program PUBLIC-OSINT 26/09/2026 05:20 Apri scheda
Vulnerabilità CVE-2026-100376Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Cr... The CVE Program PUBLIC-OSINT 26/09/2026 05:20 Apri scheda
Vulnerabilità CVE-2026-88837BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check. The CVE Program PUBLIC-OSINT 26/09/2026 05:20 Apri scheda
Vulnerabilità CVE-2026-53627GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can use the new API (v2) to perform update operations that... The CVE Program PUBLIC-OSINT 26/09/2026 05:20 Apri scheda
Vulnerabilità CVE-2026-97895A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file packages/Webkul/Admin/src/Http/Controllers/Settings/UserController.php... The CVE Program PUBLIC-OSINT 26/09/2026 05:16 Apri scheda
Vulnerabilità CVE-2026-91767php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose litera... The CVE Program PUBLIC-OSINT 26/09/2026 05:15 Apri scheda
Vulnerabilità CVE-2026-100368CliInvoke is a .NET library for invoking command-line programs, and its `CliInvoke.Specializations` packages provide specialized wrappers for shells such as PowerShell and Windo... The CVE Program PUBLIC-OSINT 26/09/2026 05:15 Apri scheda
Vulnerabilità CVE-2026-91766When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target i... The CVE Program PUBLIC-OSINT 26/09/2026 05:13 Apri scheda
Vulnerabilità CVE-2026-63206Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's HTML sanitizer, which blocks remote images in ticket articles and email views, can b... The CVE Program PUBLIC-OSINT 26/09/2026 05:11 Apri scheda
Vulnerabilità CVE-2026-56164Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network. Cybersecurity and Infrastructure Security Agency TLP:CLEAR 26/09/2026 05:09 Apri scheda
Vulnerabilità CVE-2026-97897A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file Sanitizer.php of the component TinyMCE Media Upload... The CVE Program PUBLIC-OSINT 26/09/2026 05:09 Apri scheda
Vulnerabilità CVE-2026-91768The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the e... The CVE Program PUBLIC-OSINT 26/09/2026 05:09 Apri scheda
Vulnerabilità CVE-2026-88835BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read. The CVE Program PUBLIC-OSINT 26/09/2026 05:01 Apri scheda
Vulnerabilità CVE-2026-71483Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected by jQuery .html() in employee/templates/employee_nav.html ... The CVE Program PUBLIC-OSINT 26/09/2026 05:01 Apri scheda
Vulnerabilità CVE-2026-57449Actual is a local-first personal finance tool. Prior to 26.7.0, Actual Sync Server's CORS proxy is intended to let authenticated users fetch resources only from repositories lis... The CVE Program PUBLIC-OSINT 26/09/2026 04:58 Apri scheda
Vulnerabilità CVE-2026-55214GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields. Any user who o... The CVE Program PUBLIC-OSINT 26/09/2026 04:57 Apri scheda
Vulnerabilità CVE-2026-92842The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately... The CVE Program PUBLIC-OSINT 26/09/2026 04:54 Apri scheda
Vulnerabilità CVE-2026-84463Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a user with Knowledge Base editing rights for a category can embed a video widget in a publis... The CVE Program PUBLIC-OSINT 26/09/2026 04:54 Apri scheda
Vulnerabilità CVE-2026-100389GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauth... The CVE Program PUBLIC-OSINT 26/09/2026 04:54 Apri scheda
Vulnerabilità CVE-2026-53610GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboard that reflects attacker-controlled markup without s... The CVE Program PUBLIC-OSINT 26/09/2026 04:53 Apri scheda
Vulnerabilità CVE-2026-55217GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, or delete knowledge base com... The CVE Program PUBLIC-OSINT 26/09/2026 04:49 Apri scheda
Vulnerabilità CVE-2026-100387pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent he... The CVE Program PUBLIC-OSINT 26/09/2026 04:47 Apri scheda
Vulnerabilità CVE-2026-100388RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message handler on Linux and macOS. Authent... The CVE Program PUBLIC-OSINT 26/09/2026 04:47 Apri scheda
Vulnerabilità CVE-2026-100369CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-line programs and wrapping executable processes. `CliInvoke` versions ... The CVE Program PUBLIC-OSINT 26/09/2026 04:42 Apri scheda
Vulnerabilità CVE-2026-68820Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Cybersecurity and Infrastructure Security Agency TLP:CLEAR 26/09/2026 04:41 Apri scheda
Vulnerabilità CVE-2026-100391MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query param... The CVE Program PUBLIC-OSINT 26/09/2026 04:40 Apri scheda
Vulnerabilità CVE-2026-5267Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenti... The CVE Program PUBLIC-OSINT 26/09/2026 04:39 Apri scheda
Vulnerabilità CVE-2026-78516Insertion of sensitive information into externally-accessible file or directory in Windows Storage allows an authorized attacker to disclose information locally. The CVE Program PUBLIC-OSINT 26/09/2026 04:33 Apri scheda
Vulnerabilità CVE-2026-63208Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when a Microsoft Graph request fails, Zammad logs the error including the authentication toke... The CVE Program PUBLIC-OSINT 26/09/2026 04:33 Apri scheda
Vulnerabilità CVE-2026-88003InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane fails to revoke administrative privileges after ... The CVE Program PUBLIC-OSINT 26/09/2026 04:32 Apri scheda
Vulnerabilità CVE-2026-100303TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories. Authenticated non-admin users can add, mod... The CVE Program PUBLIC-OSINT 26/09/2026 04:29 Apri scheda
Vulnerabilità CVE-2026-100372ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying... The CVE Program PUBLIC-OSINT 26/09/2026 04:28 Apri scheda
Vulnerabilità CVE-2026-79314A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy configurations of other users, including remark, port, p... The CVE Program PUBLIC-OSINT 26/09/2026 04:26 Apri scheda
Vulnerabilità CVE-2026-100378Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Translate Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects M... The CVE Program PUBLIC-OSINT 26/09/2026 04:25 Apri scheda
Vulnerabilità CVE-2026-47679GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user can exploit insufficient path validation in the profile-pi... The CVE Program PUBLIC-OSINT 26/09/2026 04:22 Apri scheda
Vulnerabilità CVE-2026-88418CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-changing admin request, and it does not send the csrf_toke... The CVE Program PUBLIC-OSINT 26/09/2026 04:18 Apri scheda
Vulnerabilità CVE-2026-65660Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. The CVE Program TLP:CLEAR 26/09/2026 04:15 Apri scheda
Vulnerabilità CVE-2026-100208Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. The CVE Program PUBLIC-OSINT 26/09/2026 04:15 Apri scheda
Vulnerabilità CVE-2026-63204Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, an authenticated user with agent permissions can supply an arbitrary AI analytics run identif... The CVE Program PUBLIC-OSINT 26/09/2026 04:14 Apri scheda
Vulnerabilità CVE-2026-57443SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4.2.1, the AetherBrowser API server (`scripts/aetherbrowse... The CVE Program PUBLIC-OSINT 26/09/2026 04:14 Apri scheda
Vulnerabilità CVE-2026-100418Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that returns the entire configuration object without field red... The CVE Program PUBLIC-OSINT 26/09/2026 04:13 Apri scheda
Vulnerabilità CVE-2026-86066Horilla is an HR and CRM software. Prior to 2.0.0, approve_validate_attendance_request at /attendance/approve-validate-attendance-request/ changes attendance_validated, is_valid... The CVE Program PUBLIC-OSINT 26/09/2026 04:09 Apri scheda
Vulnerabilità CVE-2026-78510Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. The CVE Program PUBLIC-OSINT 26/09/2026 04:07 Apri scheda
Vulnerabilità CVE-2026-55040Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. Cybersecurity and Infrastructure Security Agency TLP:CLEAR 26/09/2026 04:06 Apri scheda
Vulnerabilità CVE-2026-63207Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, an authenticated administrator can obtain stored integration credentials in cleartext thr... The CVE Program PUBLIC-OSINT 26/09/2026 04:02 Apri scheda
Vulnerabilità CVE-2026-84460Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, any authenticated user can call the REST endpoint for getting a tag list and receive the tag ... The CVE Program PUBLIC-OSINT 26/09/2026 04:00 Apri scheda
Vulnerabilità CVE-2026-49469GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria through the user... The CVE Program PUBLIC-OSINT 26/09/2026 03:55 Apri scheda
Vulnerabilità CVE-2026-100417RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from the host... The CVE Program PUBLIC-OSINT 26/09/2026 03:55 Apri scheda
Vulnerabilità CVE-2026-100382Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Com... The CVE Program PUBLIC-OSINT 26/09/2026 03:51 Apri scheda
Vulnerabilità CVE-2026-88264A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, inclu... The CVE Program PUBLIC-OSINT 26/09/2026 03:50 Apri scheda
Vulnerabilità CVE-2026-100419gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree directory via symli... The CVE Program PUBLIC-OSINT 26/09/2026 03:48 Apri scheda
Vulnerabilità CVE-2026-88340An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnerability is caused by insufficient validation of exter... The CVE Program PUBLIC-OSINT 26/09/2026 03:48 Apri scheda
Vulnerabilità CVE-2026-53626GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a document without confirming t... The CVE Program PUBLIC-OSINT 26/09/2026 03:46 Apri scheda
Vulnerabilità CVE-2026-10758Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap based Out-of-Bounds Write via Integer Overflow in LERC v... The CVE Program PUBLIC-OSINT 26/09/2026 03:45 Apri scheda
Vulnerabilità CVE-2026-84458Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on initial logon" setting is enabled, Zammad binds an incomi... The CVE Program PUBLIC-OSINT 26/09/2026 03:43 Apri scheda
Vulnerabilità CVE-2026-100390Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 ... The CVE Program PUBLIC-OSINT 26/09/2026 03:35 Apri scheda
Vulnerabilità CVE-2026-96875Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki... The CVE Program PUBLIC-OSINT 26/09/2026 03:34 Apri scheda
Vulnerabilità CVE-2026-100373OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validat... The CVE Program PUBLIC-OSINT 26/09/2026 03:30 Apri scheda
Vulnerabilità CVE-2026-95396A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unknown function of the file HospitalController.java of the ... The CVE Program PUBLIC-OSINT 26/09/2026 03:28 Apri scheda
Vulnerabilità CVE-2026-96879Improper removal of sensitive information before storage or transfer vulnerability in Wikimedia Foundation's Mediawiki - FlaggedRevs extension through 1.46.0. The CVE Program PUBLIC-OSINT 26/09/2026 03:25 Apri scheda
Vulnerabilità CVE-2026-88839BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers. The CVE Program PUBLIC-OSINT 26/09/2026 03:18 Apri scheda
Vulnerabilità CVE-2026-63432Horilla is an HR and CRM software. From 1.0.0 until 1.6.0 and 2.0.0, the get_mail_preview handlers in recruitment/views/actions.py and employee/not_in_out_dashboard.py render a ... The CVE Program PUBLIC-OSINT 26/09/2026 03:18 Apri scheda
Vulnerabilità CVE-2026-100501Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthenticated attacker... The CVE Program PUBLIC-OSINT 26/09/2026 03:17 Apri scheda
Vulnerabilità CVE-2026-97063X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to a... The CVE Program PUBLIC-OSINT 26/09/2026 03:17 Apri scheda
Vulnerabilità CVE-2026-100383Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension allows Cross-S... The CVE Program PUBLIC-OSINT 26/09/2026 03:14 Apri scheda
Vulnerabilità CVE-2026-100502Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attackers with former admin access to obtain tokens with arbitrar... The CVE Program PUBLIC-OSINT 26/09/2026 03:13 Apri scheda
Vulnerabilità CVE-2026-100305TDuck survey form through 6.0 fails to enforce form fill-in restrictions on the authenticated submission endpoint POST /user/form/data/create. Authenticated attackers who know a... The CVE Program PUBLIC-OSINT 26/09/2026 03:12 Apri scheda
Vulnerabilità CVE-2026-62699Null pointer dereference in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to execute code locally. The CVE Program PUBLIC-OSINT 26/09/2026 03:11 Apri scheda
Vulnerabilità CVE-2026-63431Horilla is an HR and CRM software. In 1.5.0-85 and earlier, payroll/views/component_views.py does not consistently authorize access in allowances_deductions_tab, view_single_all... The CVE Program PUBLIC-OSINT 26/09/2026 03:07 Apri scheda
Vulnerabilità CVE-2026-91769PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the... The CVE Program PUBLIC-OSINT 26/09/2026 03:07 Apri scheda
Vulnerabilità CVE-2026-96876Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediaw... The CVE Program PUBLIC-OSINT 26/09/2026 03:07 Apri scheda
Vulnerabilità CVE-2026-96878Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediaw... The CVE Program PUBLIC-OSINT 26/09/2026 03:03 Apri scheda
Vulnerabilità CVE-2026-53629GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can craft a URL for the history tab that in... The CVE Program PUBLIC-OSINT 26/09/2026 03:02 Apri scheda
Vulnerabilità CVE-2026-100377Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension allows Excavation. This issue affects Mediawiki... The CVE Program PUBLIC-OSINT 26/09/2026 03:00 Apri scheda
Vulnerabilità CVE-2026-51994mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata URL extracted from a remote MCP server's WWW-Authenticate header The CVE Program PUBLIC-OSINT 26/09/2026 03:00 Apri scheda
Vulnerabilità CVE-2026-58644Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Cybersecurity and Infrastructure Security Agency TLP:CLEAR 26/09/2026 02:59 Apri scheda
Vulnerabilità CVE-2026-93682When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer ... The CVE Program PUBLIC-OSINT 26/09/2026 02:59 Apri scheda
Vulnerabilità CVE-2026-96795Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns POST parameter, take... The CVE Program PUBLIC-OSINT 26/09/2026 02:56 Apri scheda
Vulnerabilità CVE-2026-91765cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousan... The CVE Program PUBLIC-OSINT 26/09/2026 02:55 Apri scheda
Vulnerabilità CVE-2026-48482GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that ... The CVE Program PUBLIC-OSINT 26/09/2026 02:54 Apri scheda
Vulnerabilità CVE-2026-63205Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email signature, Zammad processes inline images referenced in th... The CVE Program PUBLIC-OSINT 26/09/2026 02:52 Apri scheda
Vulnerabilità CVE-2026-63006Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, attacker-controlled HTML in inbound emails or tickets could bypass the image URL sanitizer us... The CVE Program PUBLIC-OSINT 26/09/2026 02:52 Apri scheda
Vulnerabilità CVE-2026-100304TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open when a form does not exist, allowing authenticated users to... The CVE Program PUBLIC-OSINT 26/09/2026 02:51 Apri scheda
Vulnerabilità CVE-2026-63216Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, unsanitized option labels are rendered in the configuration dialogs of AI Agents within Zamma... The CVE Program PUBLIC-OSINT 26/09/2026 02:46 Apri scheda
Vulnerabilità CVE-2026-84464Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's External Data Source feature, used to look up records from an external system, did n... The CVE Program PUBLIC-OSINT 26/09/2026 02:45 Apri scheda
Vulnerabilità CVE-2026-85880Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. The CVE Program TLP:CLEAR 26/09/2026 02:44 Apri scheda
Vulnerabilità CVE-2026-84465Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the digital signature on an incoming S/MIME-signed email, it does not veri... The CVE Program PUBLIC-OSINT 26/09/2026 02:39 Apri scheda
Vulnerabilità CVE-2026-84461Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try unlimited password guesses for any account with... The CVE Program PUBLIC-OSINT 26/09/2026 02:36 Apri scheda
Vulnerabilità CVE-2026-100192X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated atta... The CVE Program PUBLIC-OSINT 26/09/2026 02:36 Apri scheda
Vulnerabilità CVE-2026-100310GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attac... The CVE Program PUBLIC-OSINT 26/09/2026 02:35 Apri scheda
Vulnerabilità CVE-2026-100306TDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing the check only on the front end. Remote unauthenticated attackers can submit f... The CVE Program PUBLIC-OSINT 26/09/2026 02:32 Apri scheda
Vulnerabilità CVE-2026-96877Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediaw... The CVE Program PUBLIC-OSINT 26/09/2026 02:24 Apri scheda
Vulnerabilità CVE-2026-56155Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally. Cybersecurity and Infrastructure Security Agency TLP:CLEAR 26/09/2026 02:23 Apri scheda
Vulnerabilità CVE-2026-88831BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients. The CVE Program PUBLIC-OSINT 26/09/2026 02:21 Apri scheda
Vulnerabilità CVE-2026-97060X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Att... The CVE Program PUBLIC-OSINT 26/09/2026 02:18 Apri scheda

Questa vista non replica il database OpenCTI. Conserva solo metadati descrittivi necessari alla consultazione difensiva, con riferimenti pubblici ripuliti e classificazione di condivisione esplicita.