Database CVE
Archivio delle vulnerabilità note (CVE) con punteggio CVSS, gravità, prodotti e vendor coinvolti. Filtra per anno e severità, collegato ai nostri articoli.
- CVE-2026-7473Media5.8
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.
- CVE-2026-48907Critica9.8
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
- CVE-2026-20245Alta7.8
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on an affected system and elevate their privileges as the root user. To exploit this vulnerability, the attacker must have netadmin privileges on the affected system. This would require valid credentials or exploitation of or . Cisco is not aware of successful exploitation by other methods. Cisco has observed limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices. Cisco recommends that customers upgrade to the fixed software that is documented in the that was published on May 14, 2026, and verify the configuration of the edge devices.
- CVE-2026-28318Alta7.5
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update
- CVE-2026-8037Critica9.6
Vulnerabilità di esecuzione di codice da remoto tramite OS Command Injection nell'API dei prodotti ADC Progress consente a un attaccante non autenticato di eseguire comandi arbitrari sull'appliance LoadMaster sfruttando input non sanificato in molteplici endpoint di comando
- CVE-2026-20230Alta8.6
Una vulnerabilità in Cisco Unified Communications Manager (Unified CM) e Cisco Unified Communications Manager Session Management Edition (Unified CM SME) potrebbe consentire a un attaccante remoto non autenticato di condurre attacchi server-side request forgery (SSRF) tramite un dispositivo interessato. Questa vulnerabilità è dovuta a una convalida dell'input non corretta per specifiche richieste HTTP. Un attaccante potrebbe sfruttare questa vulnerabilità inviando una richiesta HTTP appositamente creata a un dispositivo interessato. Uno sfruttamento riuscito potrebbe consentire all'attaccante di scrivere file sul sistema operativo sottostante che potrebbero essere utilizzati in seguito per elevare i privilegi a root. Nota: Cisco ha assegnato a questo avviso di sicurezza uno Security Impact Rating (SIR) pari a Critical anziché High come indicato dal punteggio. Il motivo è che lo sfruttamento di questa vulnerabilità potrebbe consentire a un attaccante di elevare i privilegi a root. Nota: per sfruttare questa vulnerabilità, il servizio WebDialer deve essere abilitato. WebDialer è disabilitato per impostazione predefinita.
- CVE-2026-10591Alta8.8
Restrizioni insufficienti del controllo degli accessi nello strumento di scrittura di file in Amazon Kiro IDE prima della versione 0.11 potrebbero consentire ad attori remoti non autenticati di eseguire comandi arbitrari tramite istruzioni appositamente create che causano scritture in percorsi sensibili all'esecuzione (come .vscode/tasks.json), consentendo l'esecuzione automatica all'apertura della cartella. Per risolvere questo problema, gli utenti dovrebbero aggiornare Kiro IDE alla versione 0.11 o successiva.
- CVE-2025-48595Alta8.4
In più posizioni, esiste un possibile modo per ottenere l'esecuzione di codice a causa di un integer overflow. Ciò potrebbe portare a un'escalation locale dei privilegi senza necessità di privilegi di esecuzione aggiuntivi. Per lo sfruttamento non è necessaria alcuna interazione da parte dell'utente.
- CVE-2026-46817Critica9.8
Vulnerabilità nel prodotto Oracle Payments di Oracle E-Business Suite (componente: File Transmission). Le versioni supportate interessate sono 12.2.3-12.2.15. Vulnerabilità facilmente sfruttabile che consente a un attaccante non autenticato con accesso di rete tramite HTTP di compromettere Oracle Payments. Attacchi riusciti di questa vulnerabilità possono comportare l'acquisizione del controllo di Oracle Payments. Punteggio base CVSS 3.1 9.8 (impatti su riservatezza, integrità e disponibilità). Vettore CVSS: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- CVE-2026-48027Critica9.8
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx Console is not compromised and users may remediate by upgrading to that version.
- CVE-2026-48710Media6.5
Starlette è un framework/toolkit ASGI leggero. Prima della versione 1.0.1, l'header di richiesta HTTP `Host` non veniva validato prima di essere utilizzato per ricostruire `request.url`. Poiché l'algoritmo di routing si basa sul percorso HTTP grezzo mentre `request.url` viene ricostruito dall'header `Host`, un header malformato potrebbe fare in modo che `request.url.path` differisca dal percorso effettivamente richiesto. I middleware e gli endpoint che applicano restrizioni di sicurezza basate su `request.url` (anziché sul percorso `scope` grezzo) potrebbero quindi essere bypassati. Gli utenti dovrebbero aggiornare a una versione maggiore o uguale alla versione 1.0.1, che valida l'header `Host` rispetto alla grammatica di RFC 9112 §3.2 / RFC 3986 §3.2.2 durante la costruzione di `request.url` e ricorre a `scope["server"]` per i valori malformati.
- CVE-2026-45247Critica9.8
Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native unserialize() function combined with gadget chains available in Magento and its dependencies to execute arbitrary code on the server.
- CVE-2026-45659Alta8.8
La deserializzazione di dati non attendibili in Microsoft Office SharePoint consente a un utente malintenzionato autorizzato di eseguire codice in rete.
- CVE-2026-34910Critica10.0
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
- CVE-2026-34909Critica10.0
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.
- CVE-2026-34908Critica10.0
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
- CVE-2026-34926Media6.7
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.
- CVE-2026-48172Critica9.8
LiteSpeed User-End cPanel Plugin prima di 2.4.5 consente privilege escalation (possibilmente a root), come sfruttato in the wild nel maggio 2026. Il rilevamento avviene preferibilmente tramite la riga di comando grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. Se non si ottiene alcun output, non si è stati colpiti dallo sfruttamento della vulnerabilità. In presenza di output, si consiglia di esaminare gli indirizzi IP nell'elenco, determinare se sono indirizzi IP validi e, in caso contrario, bloccarli. Per determinare il danno subito, esaminare i log di sistema per l'uso da parte degli indirizzi IP rilevati. Il problema è legato alla gestione errata delle funzionalità di abilitazione/disabilitazione di Redis. La versione minima consigliata è la 2.4.7.
- CVE-2026-9082Critica9.8
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.
- CVE-2026-45498Media4.0
Microsoft Defender Denial of Service Vulnerability
This product uses the NVD API but is not endorsed or certified by the NVD.