OpenCTI · conoscenza correlata
Intelligence correlata
Entità descrittive correlate da OpenCTI e materializzate nel portale. Il flusso è unidirezionale: OpenCTI invia a Intel soltanto metadati pubblici minimizzati.
Tipologie
Tutte 73410
Gruppi e intrusion set 151
Campagne 0
Malware 7
Vulnerabilità 65538
Report 7701
Tecniche di attacco 13
Vittimologia correlata
Relazioni intrusion set → paese, periodo selezionatoPaesi bersaglio dei gruppi
Vista materializzata
200 risultati mostratiConoscenza disponibile
| Tipologia | Entità | Fonte | Condivisione | Aggiornata | |
|---|---|---|---|---|---|
| Report | lockbit5 has published a new victim: taspenlife.comTaspen Life offers a range of insurance products including health protection, group protection, and... | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:28 | Apri scheda |
| Report | lockbit5 has published a new victim: anery.com.brSomos a Anery Home Care Temos paixão por cuidar Nossa especialidade é cuidar de pessoas, com todo o... | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:28 | Apri scheda |
| Report | lockbit5 has published a new victim: corisricambi.itPresenti sul territorio da oltre un ventennio, la CO.R.I.S. S.r.l. è cresciuta all'interno del... | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:28 | Apri scheda |
| Report | incransom has published a new victim: pharma5.maPharma5 21, Rue des Asphodèles, Maârif Extension, 20100 Casablanca, Morocco 05 22 23 62 15 pharma5.ma Leaked data: 50Gb Corporate and financial information, data on products and... | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:28 | Apri scheda |
| Report | qilin has published a new victim: Iberia Compositech ManufacturingN/A | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:27 | Apri scheda |
| Report | Vexy Ransomware has published a new victim: Majani Insurance BrokersMajani Insurance Brokers is an independent insurance broker serving both businesses and individuals. It arranges insurance products across areas including general business insur... | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:27 | Apri scheda |
| Report | everest has published a new victim: ETS[AI generated] N/A "ETS" is too generic an identifier to reliably describe—there are numerous distinct organizations using this name or acronym across different industries and c... | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:27 | Apri scheda |
| Report | everest has published a new victim: CENELEC[AI generated] CENELEC (European Committee for Electrotechnical Standardization) is a Brussels, Belgium-based standardization organization operating across Europe. It develops v... | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:27 | Apri scheda |
| Report | everest has published a new victim: UNIRITA[AI generated] UNIRITA Inc. is a Japanese IT company headquartered in Tokyo, Japan, operating in the information technology and systems software industry. It specializes in IT o... | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:27 | Apri scheda |
| Report | everest has published a new victim: Reliance Audit[AI generated] N/A I don't have verified, reliable information about a specific company named "Reliance Audit." This name is generic and could refer to multiple small firms or l... | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:27 | Apri scheda |
| Report | Wallstreet has published a new victim: Breast Implant Center of HawaiiBreast Implant Center of Hawaii is a plastic surgery and aesthetics clinic serving patients across Hawaii. Based in Kailua-Kona, it offers breast augmentation, implant revision,... | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:27 | Apri scheda |
| Report | Wallstreet has published a new victim: Tobin & CompanyTobin & Company, CPA’s is a small accounting firm based in Harrison, New York, providing accounting, tax, auditing, and business consulting services, with a particular focus on ... | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:27 | Apri scheda |
| Report | Wallstreet has published a new victim: Ar Valve ResourcesAR Valve Resources is a UK-based distributor of industrial valves, actuators, regulators, instrumentation, and spare parts. Based in Kent, the company serves national and intern... | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:27 | Apri scheda |
| Report | Wallstreet has published a new victim: GTFMGTFM LLC is a company operating through gtfmllc.com. Its website currently provides limited publicly accessible information, so its specific products or services could not be confirmed. | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:27 | Apri scheda |
| Report | everest has published a new victim: Morula IVF[AI generated] Morula IVF is a network of fertility clinics operating in Indonesia, specializing in in vitro fertilization (IVF) and other assisted reproductive technologies. It... | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:27 | Apri scheda |
| Report | Wallstreet has published a new victim: Beatus CartonsBeatus Cartons is a UK-based, privately owned manufacturer of printed folding cartons and packaging. Established in 1940, it produces solidboard, litho-laminated, and plastic pa... | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:27 | Apri scheda |
| Report | emperador has published a new victim: Electrolux & OntracHello Electrolux & OnTrac, Still no response from you. When we called your IT helpdesk posing as threat researchers and asked about the breach, we were told, "We cannot talk abo... | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:27 | Apri scheda |
| Report | everest has published a new victim: Securitas Group[AI generated] Securitas Group is a Swedish multinational security services company headquartered in Stockholm, Sweden. It operates in the security industry, providing guarding ... | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:27 | Apri scheda |
| Report | metaencryptor has published a new victim: Platinum Healthcare StaffingPlatinum Healthcare Staffing is a healthcare staffing agency headquartered in Lafayette, USA, founded in 2005. It provides nursing and allied healthcare professionals, including... | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:27 | Apri scheda |
| Report | metaencryptor has published a new victim: PKF HadiwinataPKF Hadiwinata is a top-10 accounting and professional services firm in Indonesia, headquartered in the financial district of Jakarta. Founded in 1987, it is a member of PKF Int... | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:27 | Apri scheda |
| Report | metaencryptor has published a new victim: GE Vernova Inc.GE Vernova Inc. is a global energy equipment manufacturing and services company headquartered in Cambridge, Massachusetts. Formed from General Electric's energy businesses, it o... | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:27 | Apri scheda |
| Report | SilentRansomGroup has published a new victim: S...Redacted entry - full company name pending disclosure (FULL DATA TIMER active). | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:26 | Apri scheda |
| Report | SilentRansomGroup has published a new victim: N...Redacted entry - full company name pending disclosure (FULL DATA TIMER active). | Ransomware.Live | TLP:CLEAR | 26/09/2026 10:26 | Apri scheda |
| Vulnerabilità | CVE-2026-100581OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the device Keychain. Attackers with access to unencrypted dev... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:16 | Apri scheda |
| Vulnerabilità | CVE-2026-100523Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain validation. Unauthenticated attackers can ... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:15 | Apri scheda |
| Vulnerabilità | CVE-2026-15273The Automatic.css plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI in all version 4.0.0 due to insufficient input sanitization and output escapi... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:15 | Apri scheda |
| Vulnerabilità | CVE-2026-100540OpenClaw Feishu before 2026.8.1 fails to validate whether a configured default account is disabled before selecting it for model tool operations. Attackers can exploit multi-acc... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:15 | Apri scheda |
| Vulnerabilità | CVE-2026-100536OpenClaw versions before 2026.8.1 fail to validate all source fields in structured message attachments, allowing attackers to hide unvalidated host paths behind allowed attachme... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:15 | Apri scheda |
| Vulnerabilità | CVE-2026-100525The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prometheus) before version 2026.9.3 does not enforce the operator.read scope on its authenticated metrics endpo... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:15 | Apri scheda |
| Vulnerabilità | CVE-2026-100529OpenClaw versions before 2026.8.1 contain an authorization scope widening vulnerability in file-transfer allow-always approvals that allows attackers to reuse standing grants fo... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:15 | Apri scheda |
| Vulnerabilità | CVE-2026-100594OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the /export-trajectory endpoint that allows non-owner senders to request and receive owner-onl... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:15 | Apri scheda |
| Vulnerabilità | CVE-2026-100570OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the CLOUDSDK_PYTHON_ARGS environment variable. When an opera... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:15 | Apri scheda |
| Vulnerabilità | CVE-2026-100503Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter function caused by stale INDIRECT effect-op references. At... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:15 | Apri scheda |
| Vulnerabilità | CVE-2026-100534OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions. An attacker ... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:15 | Apri scheda |
| Vulnerabilità | CVE-2026-100586OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:15 | Apri scheda |
| Vulnerabilità | CVE-2026-100563OpenClaw (npm package `openclaw`) before 2026.8.1 does not neutralize leading characters that spreadsheet applications interpret as formulas when the Control UI exports session ... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:15 | Apri scheda |
| Vulnerabilità | CVE-2026-100578OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the chat.send endpoint. In Gateway deployments using authenti... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:15 | Apri scheda |
| Vulnerabilità | CVE-2026-100584OpenClaw is an npm-distributed agent runtime. In versions >= 2026.2.26 and < 2026.7.1, PowerShell command analysis on Windows hosts running in exec allowlist mode could approve ... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:15 | Apri scheda |
| Vulnerabilità | CVE-2026-96258A vulnerability has been found in onSite internet GmbH Auktion NG Auktionssoftware up to 20260722. This affects an unknown part of the file /forgotpasswd.html of the component P... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:15 | Apri scheda |
| Vulnerabilità | CVE-2026-100572OpenClaw versions >= 2026.3.25 and < 2026.8.1 apply invalid-token rate limiting for Synology Chat webhooks before authentication and key the limit on the raw proxy socket addres... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:15 | Apri scheda |
| Vulnerabilità | CVE-2026-100556OpenClaw (npm package openclaw) versions >= 2026.5.2 and command to reset the shared group session and persist a provider and model override. This allows a command-denied group ... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:15 | Apri scheda |
| Vulnerabilità | CVE-2026-100571OpenClaw (npm package 'openclaw') versions >= 2026.6.6 and < 2026.8.1 apply the SMS webhook invalid-request rate limit before Twilio signature verification and identify clients ... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:15 | Apri scheda |
| Vulnerabilità | CVE-2026-100597OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror filesystem mutation operations. The remov... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:15 | Apri scheda |
| Vulnerabilità | CVE-2026-100590OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner external-channel senders to persist Gateway voice configu... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:15 | Apri scheda |
| Vulnerabilità | CVE-2026-100558OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauthenticated clients to retain response sockets by sending W... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:15 | Apri scheda |
| Vulnerabilità | CVE-2026-100554OpenClaw (npm package 'openclaw') versions >= 2026.5.12 and < 2026.8.1 do not immediately invalidate Canvas HTTP authorization when a paired node is revoked. Node revocation inv... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100532@openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the o... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100587OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation command. Non-owner channel senders can install arbitrary p... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100592OpenClaw is an agent gateway distributed via npm. In versions >= 2026.4.10 and < 2026.7.1, persistent memory dreaming mutations omit owner permission checks. An authorized but n... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100599OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The googlemeet.chrome command accepts caller-supplied a... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100591OpenClaw is an npm-distributed agent gateway. In versions before 2026.7.1, the global Active Memory toggle mutations could omit owner checks. An authorized non-owner external-ch... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100504Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 function when processing negative shift amounts from p-co... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100595OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the diagnostics export command that allows non-owner channel senders to access owner-only host... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100577OpenClaw versions before 2026.8.1 fail to validate video asset URLs returned by providers, allowing server-side requests to private destinations. A malicious or compromised prov... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100527OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending-authentication ... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-95924A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_f... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100560OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. A... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100583OpenClaw Discord versions before 2026.7.1 contain an authorization bypass vulnerability in guild metadata read actions that allows lower-trust senders to retrieve information ex... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100574OpenClaw (npm package 'openclaw') before 2026.8.1 contains a server-side request forgery vulnerability in its trusted-host DNS checks. For fetches that use the trusted-host DNS ... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100585OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code permission prompts delivered through the MCP channel ... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100549OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in QQBot voice attachment handling where filenames are decoded twice, allowing encoded traversal segment... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100588OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, alth... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-95657A vulnerability was determined in dgtlmoon Changedetection.io up to 0.55.8. This issue affects the function setCurrentSelectedText of the file changedetectionio/static/js/visual... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100539OpenClaw (npm package 'openclaw') before 2026.8.1 fails to revoke memory tool access when an operator hot-disables memory configuration. Existing memory_search and memory_get to... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100559OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers ca... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100543OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100546OpenClaw (npm package `openclaw`) versions >= 2026.7.2 and < 2026.9.2 contain a race condition in the Discord realtime voice transcript path. Concurrent control-classified voice... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100593OpenClaw (npm package `openclaw`) before 2026.7.1 does not enforce the documented owner-only requirement for persistent `/activation` policy changes in group channels. An author... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100569OpenClaw is an npm-distributed application. In versions >= 2026.4.25 and < 2026.8.1, the workspace environment-variable filter did not block variables ending in `_ENDPOINT`, so ... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:13 | Apri scheda |
| Vulnerabilità | CVE-2026-100553OpenClaw versions >= 2026.6.9 and < 2026.8.1 do not declare the native chatId parameter as a delivery target in the Feishu unpin feature, so unpin requests can bypass the shared... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:13 | Apri scheda |
| Vulnerabilità | CVE-2026-100505Ghidra versions 11.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when decoding multi-byte UTF-8, UTF-16, or UTF-32 characters w... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:13 | Apri scheda |
| Vulnerabilità | CVE-2026-100538OpenClaw (npm package 'openclaw') before 2026.8.1 does not apply the originating sender's global or per-agent toolsBySender policy when handling outbound attachments. A sender t... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:13 | Apri scheda |
| Vulnerabilità | CVE-2026-100535OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is per... | The CVE Program | PUBLIC-OSINT | 26/09/2026 08:13 | Apri scheda |
| Vulnerabilità | CVE-2026-6103phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide and holds values up to 0x1FFFFFFFF, so a ... | The CVE Program | PUBLIC-OSINT | 26/09/2026 05:34 | Apri scheda |
| Vulnerabilità | CVE-2026-100381Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - UploadWizard Extension allows Cross... | The CVE Program | PUBLIC-OSINT | 26/09/2026 05:32 | Apri scheda |
| Vulnerabilità | CVE-2026-81963Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. | The CVE Program | TLP:CLEAR | 26/09/2026 05:32 | Apri scheda |
| Vulnerabilità | CVE-2026-67279RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a sess... | The CVE Program | TLP:CLEAR | 26/09/2026 05:31 | Apri scheda |
| Vulnerabilità | CVE-2026-100379Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App allows Accessing/Intercepting/Modifying HTTP Cookies. This... | The CVE Program | PUBLIC-OSINT | 26/09/2026 05:28 | Apri scheda |
| Vulnerabilità | CVE-2026-97884A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatestuden... | The CVE Program | PUBLIC-OSINT | 26/09/2026 05:27 | Apri scheda |
| Vulnerabilità | CVE-2026-53628GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding the Update auth and sync or Update auth, sync and 2FA right... | The CVE Program | PUBLIC-OSINT | 26/09/2026 05:22 | Apri scheda |
| Vulnerabilità | CVE-2026-53625GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through the API to change another use... | The CVE Program | PUBLIC-OSINT | 26/09/2026 05:22 | Apri scheda |
| Vulnerabilità | CVE-2026-45801GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user without the required permission can enable debug mode. The aff... | The CVE Program | PUBLIC-OSINT | 26/09/2026 05:20 | Apri scheda |
| Vulnerabilità | CVE-2026-97896A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationForm::rules of the file packages/Webkul/Admin/src/Http/Req... | The CVE Program | PUBLIC-OSINT | 26/09/2026 05:20 | Apri scheda |
| Vulnerabilità | CVE-2026-88832BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images. | The CVE Program | PUBLIC-OSINT | 26/09/2026 05:20 | Apri scheda |
| Vulnerabilità | CVE-2026-100376Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Cr... | The CVE Program | PUBLIC-OSINT | 26/09/2026 05:20 | Apri scheda |
| Vulnerabilità | CVE-2026-88837BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check. | The CVE Program | PUBLIC-OSINT | 26/09/2026 05:20 | Apri scheda |
| Vulnerabilità | CVE-2026-53627GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can use the new API (v2) to perform update operations that... | The CVE Program | PUBLIC-OSINT | 26/09/2026 05:20 | Apri scheda |
| Vulnerabilità | CVE-2026-97895A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file packages/Webkul/Admin/src/Http/Controllers/Settings/UserController.php... | The CVE Program | PUBLIC-OSINT | 26/09/2026 05:16 | Apri scheda |
| Vulnerabilità | CVE-2026-91767php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose litera... | The CVE Program | PUBLIC-OSINT | 26/09/2026 05:15 | Apri scheda |
| Vulnerabilità | CVE-2026-100368CliInvoke is a .NET library for invoking command-line programs, and its `CliInvoke.Specializations` packages provide specialized wrappers for shells such as PowerShell and Windo... | The CVE Program | PUBLIC-OSINT | 26/09/2026 05:15 | Apri scheda |
| Vulnerabilità | CVE-2026-91766When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target i... | The CVE Program | PUBLIC-OSINT | 26/09/2026 05:13 | Apri scheda |
| Vulnerabilità | CVE-2026-63206Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's HTML sanitizer, which blocks remote images in ticket articles and email views, can b... | The CVE Program | PUBLIC-OSINT | 26/09/2026 05:11 | Apri scheda |
| Vulnerabilità | CVE-2026-56164Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network. | Cybersecurity and Infrastructure Security Agency | TLP:CLEAR | 26/09/2026 05:09 | Apri scheda |
| Vulnerabilità | CVE-2026-97897A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file Sanitizer.php of the component TinyMCE Media Upload... | The CVE Program | PUBLIC-OSINT | 26/09/2026 05:09 | Apri scheda |
| Vulnerabilità | CVE-2026-91768The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the e... | The CVE Program | PUBLIC-OSINT | 26/09/2026 05:09 | Apri scheda |
| Vulnerabilità | CVE-2026-88835BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read. | The CVE Program | PUBLIC-OSINT | 26/09/2026 05:01 | Apri scheda |
| Vulnerabilità | CVE-2026-71483Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected by jQuery .html() in employee/templates/employee_nav.html ... | The CVE Program | PUBLIC-OSINT | 26/09/2026 05:01 | Apri scheda |
| Vulnerabilità | CVE-2026-57449Actual is a local-first personal finance tool. Prior to 26.7.0, Actual Sync Server's CORS proxy is intended to let authenticated users fetch resources only from repositories lis... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:58 | Apri scheda |
| Vulnerabilità | CVE-2026-55214GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields. Any user who o... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:57 | Apri scheda |
| Vulnerabilità | CVE-2026-92842The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:54 | Apri scheda |
| Vulnerabilità | CVE-2026-84463Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a user with Knowledge Base editing rights for a category can embed a video widget in a publis... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:54 | Apri scheda |
| Vulnerabilità | CVE-2026-100389GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauth... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:54 | Apri scheda |
| Vulnerabilità | CVE-2026-53610GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboard that reflects attacker-controlled markup without s... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:53 | Apri scheda |
| Vulnerabilità | CVE-2026-55217GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, or delete knowledge base com... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:49 | Apri scheda |
| Vulnerabilità | CVE-2026-100387pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent he... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:47 | Apri scheda |
| Vulnerabilità | CVE-2026-100388RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message handler on Linux and macOS. Authent... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:47 | Apri scheda |
| Vulnerabilità | CVE-2026-100369CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-line programs and wrapping executable processes. `CliInvoke` versions ... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:42 | Apri scheda |
| Vulnerabilità | CVE-2026-68820Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | Cybersecurity and Infrastructure Security Agency | TLP:CLEAR | 26/09/2026 04:41 | Apri scheda |
| Vulnerabilità | CVE-2026-100391MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query param... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:40 | Apri scheda |
| Vulnerabilità | CVE-2026-5267Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenti... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:39 | Apri scheda |
| Vulnerabilità | CVE-2026-78516Insertion of sensitive information into externally-accessible file or directory in Windows Storage allows an authorized attacker to disclose information locally. | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:33 | Apri scheda |
| Vulnerabilità | CVE-2026-63208Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when a Microsoft Graph request fails, Zammad logs the error including the authentication toke... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:33 | Apri scheda |
| Vulnerabilità | CVE-2026-88003InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane fails to revoke administrative privileges after ... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:32 | Apri scheda |
| Vulnerabilità | CVE-2026-100303TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories. Authenticated non-admin users can add, mod... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:29 | Apri scheda |
| Vulnerabilità | CVE-2026-100372ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:28 | Apri scheda |
| Vulnerabilità | CVE-2026-79314A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy configurations of other users, including remark, port, p... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:26 | Apri scheda |
| Vulnerabilità | CVE-2026-100378Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Translate Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects M... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:25 | Apri scheda |
| Vulnerabilità | CVE-2026-47679GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user can exploit insufficient path validation in the profile-pi... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:22 | Apri scheda |
| Vulnerabilità | CVE-2026-88418CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-changing admin request, and it does not send the csrf_toke... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:18 | Apri scheda |
| Vulnerabilità | CVE-2026-65660Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | The CVE Program | TLP:CLEAR | 26/09/2026 04:15 | Apri scheda |
| Vulnerabilità | CVE-2026-100208Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:15 | Apri scheda |
| Vulnerabilità | CVE-2026-63204Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, an authenticated user with agent permissions can supply an arbitrary AI analytics run identif... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:14 | Apri scheda |
| Vulnerabilità | CVE-2026-57443SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4.2.1, the AetherBrowser API server (`scripts/aetherbrowse... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100418Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that returns the entire configuration object without field red... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:13 | Apri scheda |
| Vulnerabilità | CVE-2026-86066Horilla is an HR and CRM software. Prior to 2.0.0, approve_validate_attendance_request at /attendance/approve-validate-attendance-request/ changes attendance_validated, is_valid... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:09 | Apri scheda |
| Vulnerabilità | CVE-2026-78510Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:07 | Apri scheda |
| Vulnerabilità | CVE-2026-55040Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. | Cybersecurity and Infrastructure Security Agency | TLP:CLEAR | 26/09/2026 04:06 | Apri scheda |
| Vulnerabilità | CVE-2026-63207Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, an authenticated administrator can obtain stored integration credentials in cleartext thr... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:02 | Apri scheda |
| Vulnerabilità | CVE-2026-84460Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, any authenticated user can call the REST endpoint for getting a tag list and receive the tag ... | The CVE Program | PUBLIC-OSINT | 26/09/2026 04:00 | Apri scheda |
| Vulnerabilità | CVE-2026-49469GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria through the user... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:55 | Apri scheda |
| Vulnerabilità | CVE-2026-100417RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from the host... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:55 | Apri scheda |
| Vulnerabilità | CVE-2026-100382Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Com... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:51 | Apri scheda |
| Vulnerabilità | CVE-2026-88264A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, inclu... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:50 | Apri scheda |
| Vulnerabilità | CVE-2026-100419gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree directory via symli... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:48 | Apri scheda |
| Vulnerabilità | CVE-2026-88340An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnerability is caused by insufficient validation of exter... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:48 | Apri scheda |
| Vulnerabilità | CVE-2026-53626GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a document without confirming t... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:46 | Apri scheda |
| Vulnerabilità | CVE-2026-10758Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap based Out-of-Bounds Write via Integer Overflow in LERC v... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:45 | Apri scheda |
| Vulnerabilità | CVE-2026-84458Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on initial logon" setting is enabled, Zammad binds an incomi... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:43 | Apri scheda |
| Vulnerabilità | CVE-2026-100390Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 ... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:35 | Apri scheda |
| Vulnerabilità | CVE-2026-96875Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:34 | Apri scheda |
| Vulnerabilità | CVE-2026-100373OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validat... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:30 | Apri scheda |
| Vulnerabilità | CVE-2026-95396A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unknown function of the file HospitalController.java of the ... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:28 | Apri scheda |
| Vulnerabilità | CVE-2026-96879Improper removal of sensitive information before storage or transfer vulnerability in Wikimedia Foundation's Mediawiki - FlaggedRevs extension through 1.46.0. | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:25 | Apri scheda |
| Vulnerabilità | CVE-2026-88839BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers. | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:18 | Apri scheda |
| Vulnerabilità | CVE-2026-63432Horilla is an HR and CRM software. From 1.0.0 until 1.6.0 and 2.0.0, the get_mail_preview handlers in recruitment/views/actions.py and employee/not_in_out_dashboard.py render a ... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:18 | Apri scheda |
| Vulnerabilità | CVE-2026-100501Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthenticated attacker... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:17 | Apri scheda |
| Vulnerabilità | CVE-2026-97063X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to a... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:17 | Apri scheda |
| Vulnerabilità | CVE-2026-100383Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension allows Cross-S... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:14 | Apri scheda |
| Vulnerabilità | CVE-2026-100502Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attackers with former admin access to obtain tokens with arbitrar... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:13 | Apri scheda |
| Vulnerabilità | CVE-2026-100305TDuck survey form through 6.0 fails to enforce form fill-in restrictions on the authenticated submission endpoint POST /user/form/data/create. Authenticated attackers who know a... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:12 | Apri scheda |
| Vulnerabilità | CVE-2026-62699Null pointer dereference in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to execute code locally. | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:11 | Apri scheda |
| Vulnerabilità | CVE-2026-63431Horilla is an HR and CRM software. In 1.5.0-85 and earlier, payroll/views/component_views.py does not consistently authorize access in allowances_deductions_tab, view_single_all... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:07 | Apri scheda |
| Vulnerabilità | CVE-2026-91769PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:07 | Apri scheda |
| Vulnerabilità | CVE-2026-96876Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediaw... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:07 | Apri scheda |
| Vulnerabilità | CVE-2026-96878Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediaw... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:03 | Apri scheda |
| Vulnerabilità | CVE-2026-53629GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can craft a URL for the history tab that in... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:02 | Apri scheda |
| Vulnerabilità | CVE-2026-100377Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension allows Excavation. This issue affects Mediawiki... | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:00 | Apri scheda |
| Vulnerabilità | CVE-2026-51994mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata URL extracted from a remote MCP server's WWW-Authenticate header | The CVE Program | PUBLIC-OSINT | 26/09/2026 03:00 | Apri scheda |
| Vulnerabilità | CVE-2026-58644Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | Cybersecurity and Infrastructure Security Agency | TLP:CLEAR | 26/09/2026 02:59 | Apri scheda |
| Vulnerabilità | CVE-2026-93682When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer ... | The CVE Program | PUBLIC-OSINT | 26/09/2026 02:59 | Apri scheda |
| Vulnerabilità | CVE-2026-96795Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns POST parameter, take... | The CVE Program | PUBLIC-OSINT | 26/09/2026 02:56 | Apri scheda |
| Vulnerabilità | CVE-2026-91765cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousan... | The CVE Program | PUBLIC-OSINT | 26/09/2026 02:55 | Apri scheda |
| Vulnerabilità | CVE-2026-48482GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that ... | The CVE Program | PUBLIC-OSINT | 26/09/2026 02:54 | Apri scheda |
| Vulnerabilità | CVE-2026-63205Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email signature, Zammad processes inline images referenced in th... | The CVE Program | PUBLIC-OSINT | 26/09/2026 02:52 | Apri scheda |
| Vulnerabilità | CVE-2026-63006Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, attacker-controlled HTML in inbound emails or tickets could bypass the image URL sanitizer us... | The CVE Program | PUBLIC-OSINT | 26/09/2026 02:52 | Apri scheda |
| Vulnerabilità | CVE-2026-100304TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open when a form does not exist, allowing authenticated users to... | The CVE Program | PUBLIC-OSINT | 26/09/2026 02:51 | Apri scheda |
| Vulnerabilità | CVE-2026-63216Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, unsanitized option labels are rendered in the configuration dialogs of AI Agents within Zamma... | The CVE Program | PUBLIC-OSINT | 26/09/2026 02:46 | Apri scheda |
| Vulnerabilità | CVE-2026-84464Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's External Data Source feature, used to look up records from an external system, did n... | The CVE Program | PUBLIC-OSINT | 26/09/2026 02:45 | Apri scheda |
| Vulnerabilità | CVE-2026-85880Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. | The CVE Program | TLP:CLEAR | 26/09/2026 02:44 | Apri scheda |
| Vulnerabilità | CVE-2026-84465Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the digital signature on an incoming S/MIME-signed email, it does not veri... | The CVE Program | PUBLIC-OSINT | 26/09/2026 02:39 | Apri scheda |
| Vulnerabilità | CVE-2026-84461Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try unlimited password guesses for any account with... | The CVE Program | PUBLIC-OSINT | 26/09/2026 02:36 | Apri scheda |
| Vulnerabilità | CVE-2026-100192X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated atta... | The CVE Program | PUBLIC-OSINT | 26/09/2026 02:36 | Apri scheda |
| Vulnerabilità | CVE-2026-100310GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attac... | The CVE Program | PUBLIC-OSINT | 26/09/2026 02:35 | Apri scheda |
| Vulnerabilità | CVE-2026-100306TDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing the check only on the front end. Remote unauthenticated attackers can submit f... | The CVE Program | PUBLIC-OSINT | 26/09/2026 02:32 | Apri scheda |
| Vulnerabilità | CVE-2026-96877Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediaw... | The CVE Program | PUBLIC-OSINT | 26/09/2026 02:24 | Apri scheda |
| Vulnerabilità | CVE-2026-56155Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally. | Cybersecurity and Infrastructure Security Agency | TLP:CLEAR | 26/09/2026 02:23 | Apri scheda |
| Vulnerabilità | CVE-2026-88831BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients. | The CVE Program | PUBLIC-OSINT | 26/09/2026 02:21 | Apri scheda |
| Vulnerabilità | CVE-2026-97060X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Att... | The CVE Program | PUBLIC-OSINT | 26/09/2026 02:18 | Apri scheda |
| Vulnerabilità | CVE-2026-49470GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password verification endpoint does not limit failed submissions per u... | The CVE Program | PUBLIC-OSINT | 26/09/2026 02:10 | Apri scheda |
| Vulnerabilità | CVE-2026-97064X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate ... | The CVE Program | PUBLIC-OSINT | 26/09/2026 02:04 | Apri scheda |
| Vulnerabilità | CVE-2026-61855Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, under certain conditions, Zammad's verification of inbound PGP-signed email can mark a me... | The CVE Program | PUBLIC-OSINT | 26/09/2026 02:01 | Apri scheda |
| Vulnerabilità | CVE-2026-88414MCMS 6.1.1 through 6.2.1 contains a SQL injection vulnerability in the PageAction.verify endpoint (GET /ms/mdiy/page/verify.do). | The CVE Program | PUBLIC-OSINT | 26/09/2026 02:00 | Apri scheda |
| Vulnerabilità | CVE-2026-50522Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | Cybersecurity and Infrastructure Security Agency | TLP:CLEAR | 26/09/2026 01:59 | Apri scheda |
| Vulnerabilità | CVE-2026-17545On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$ when they appear as a... | The CVE Program | PUBLIC-OSINT | 26/09/2026 01:58 | Apri scheda |
| Vulnerabilità | CVE-2026-87902An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant... | The CVE Program | TLP:CLEAR | 26/09/2026 01:53 | Apri scheda |
| Vulnerabilità | CVE-2026-32201Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network. | Cybersecurity and Infrastructure Security Agency | TLP:CLEAR | 26/09/2026 01:51 | Apri scheda |
| Vulnerabilità | CVE-2026-33825Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally. | Cybersecurity and Infrastructure Security Agency | TLP:CLEAR | 26/09/2026 01:50 | Apri scheda |
| Vulnerabilità | CVE-2026-32202Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network. | Cybersecurity and Infrastructure Security Agency | TLP:CLEAR | 26/09/2026 01:50 | Apri scheda |
| Vulnerabilità | CVE-2026-100380Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Cross-Sit... | The CVE Program | PUBLIC-OSINT | 26/09/2026 01:50 | Apri scheda |
| Vulnerabilità | CVE-2026-33824Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution. | Cybersecurity and Infrastructure Security Agency | TLP:CLEAR | 26/09/2026 01:47 | Apri scheda |
| Vulnerabilità | CVE-2026-71362Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive res... | The CVE Program | TLP:CLEAR | 26/09/2026 01:44 | Apri scheda |
| Vulnerabilità | CVE-2026-5430WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote ... | The CVE Program | TLP:CLEAR | 26/09/2026 01:44 | Apri scheda |
| Report | pear has published a new victim: Indroj Medical Group Inc.The Web's Free NPI Registry Search & Provider Reference Site | Ransomware.Live | TLP:CLEAR | 25/09/2026 22:27 | Apri scheda |
| Report | pear has published a new victim: Martin Lawrence GalleriesPremier gallery of fine art in America | Ransomware.Live | TLP:CLEAR | 25/09/2026 22:27 | Apri scheda |
| Report | pear has published a new victim: Westside GIAmbulatory endoscopy center | Ransomware.Live | TLP:CLEAR | 25/09/2026 22:26 | Apri scheda |
| Report | Spirals has published a new victim: Armada Credit BureauArmada Credit Bureau Limited is a duly licensed credit reporting and analytics company | Ransomware.Live | TLP:CLEAR | 25/09/2026 22:26 | Apri scheda |
| Report | N0n has published a new victim: TapClicks (marketing analytics platform)Marketing analytics / SaaS · United States | The complete platform source code (97,000+ commits with full history); The multi-tenant instance management system with production a... | Ransomware.Live | TLP:CLEAR | 25/09/2026 22:26 | Apri scheda |
| Vulnerabilità | CVE-2026-97883A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the fil... | The CVE Program | PUBLIC-OSINT | 25/09/2026 21:03 | Apri scheda |
| Vulnerabilità | CVE-2026-100177The AIL Framework crawler task creation API (api_add_crawler_task) contained an insufficient authorization check when a user supplied a cookiejar UUID to attach to a one-shot or... | The CVE Program | PUBLIC-OSINT | 25/09/2026 21:03 | Apri scheda |
| Vulnerabilità | CVE-2026-56723Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, a customer who can view a ticket cannot see internal ticket articles through the article list... | The CVE Program | PUBLIC-OSINT | 25/09/2026 21:03 | Apri scheda |
Questa vista non replica il database OpenCTI. Conserva solo metadati descrittivi necessari alla consultazione difensiva, con riferimenti pubblici ripuliti e classificazione di condivisione esplicita.