MarfedLab
SECURITY PULSE · FONTI UFFICIALI

Security Intelligence

Un digest giornaliero per capire cosa richiede attenzione e quali verifiche avviare.

Ultimo aggiornamento:
C
76Nuove CVE criticheUltimi 7 giorni
K
103Vulnerabilità sfruttateCatalogo CISA KEV
M
2674Aggiornamenti MicrosoftUltimi 30 giorni
P
205Advisory prioritariRichiedono attenzione
T
2781Elementi indicizzatiArchivio ricercabile
IL DIGEST DI OGGI

Ciò che conta davvero

Selezione automatica per sfruttamento attivo, severità, diffusione e rilevanza enterprise.

01
HIGHKEVCVE-2026-56155CVSS 7,8
Microsoft MSRC

CVE-2026-56155 · Active Directory Federation Services Elevation of Privilege Vulnerability

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

02
MEDIUMKEVCVE-2026-56164CVSS 5,3
Microsoft MSRC

CVE-2026-56164 · Microsoft SharePoint Server Elevation of Privilege Vulnerability

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

03
CRITICALKEVCVE-2026-58644CVSS 9,8
Microsoft MSRC

CVE-2026-58644 · Microsoft SharePoint Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

04
CRITICALKEVCVE-2020-29583
CISA KEV

CVE-2020-29583 · Zyxel Multiple Products

Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password.

05
CRITICALKEVCVE-2019-8394
CISA KEV

CVE-2019-8394 · Zoho ManageEngine

Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.

12 risultati
HIGHKEVCVE-2026-56155CVSS 7,8
28 Lug 2026

CVE-2026-56155 · Active Directory Federation Services Elevation of Privilege Vulnerability

microsoft · Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019 +12

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

MEDIUMKEVCVE-2026-56164CVSS 5,3
28 Lug 2026

CVE-2026-56164 · Microsoft SharePoint Server Elevation of Privilege Vulnerability

microsoft · Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

CRITICALKEVCVE-2026-58644CVSS 9,8
28 Lug 2026

CVE-2026-58644 · Microsoft SharePoint Remote Code Execution Vulnerability

microsoft · Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CRITICALKEVCVE-2020-29583
03 Nov 2021

CVE-2020-29583 · Zyxel Multiple Products

zyxel · Multiple Products

Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password.

ZY
CRITICALKEVCVE-2019-8394
03 Nov 2021

CVE-2019-8394 · Zoho ManageEngine

zoho · ManageEngine

Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.

ZO
CRITICALKEVCVE-2020-10189
03 Nov 2021

CVE-2020-10189 · Zoho ManageEngine

zoho · ManageEngine

Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution.

ZO
CRITICALKEVCVE-2021-40539
03 Nov 2021

CVE-2021-40539 · Zoho ManageEngine

zoho · ManageEngine

Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.

ZO
CRITICALKEVCVE-2021-27561
03 Nov 2021

CVE-2021-27561 · Yealink Device Management

yealink · Device Management

Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution.

YE
CRITICALKEVCVE-2019-9978
03 Nov 2021

CVE-2019-9978 · WordPress Social Warfare Plugin

wordpress · Social Warfare Plugin

WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.

WO
CRITICALKEVCVE-2020-11738
03 Nov 2021

CVE-2020-11738 · WordPress Snap Creek Duplicator Plugin

wordpress · Snap Creek Duplicator Plugin

WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro.

WO
CRITICALKEVCVE-2020-25213
03 Nov 2021

CVE-2020-25213 · WordPress File Manager Plugin

wordpress · File Manager Plugin

WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.

WO
CRITICALKEVCVE-2020-4006
03 Nov 2021

CVE-2020-4006 · VMware Multiple Products

vmware · Multiple Products

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system.

VM