PULSE
EN VIVO24señales / 24h
FEED
ransomqilin reclama a Galvin Brothers · IE · Manufacturingransomqilin reclama a RUPP Spritzguss · DE · Manufacturingransomkrybit reclama a cesmac.edu.br · BR · Educationransomincransom reclama a TRULITE GLASS & ALUMINUM SOLUTIONS · US · Manufacturingransomplay reclama a First Tek · TW · Technologyransomplay reclama a Preferred Financial Group · US · Financial Servicesransomthegentlemen reclama a TopMark Funding · US · Financial Servicesransomthegentlemen reclama a Control Concepts Technology · US · Technologyransomchaos reclama a healthcarehighways.com · US · Healthcareransomgunra reclama a worldtube · KR · Technologyransomqilin reclama a WD Masonry & Concrete · US · Otherransomakira reclama a University SprinklerSystems · Manufacturingransomorova reclama a Tat Fung Textile Co., Ltd. · HK · Manufacturingransomorova reclama a Integrated Site Management · US · Professional Servicesransomqilin reclama a Galvin Brothers · IE · Manufacturingransomqilin reclama a RUPP Spritzguss · DE · Manufacturingransomkrybit reclama a cesmac.edu.br · BR · Educationransomincransom reclama a TRULITE GLASS & ALUMINUM SOLUTIONS · US · Manufacturingransomplay reclama a First Tek · TW · Technologyransomplay reclama a Preferred Financial Group · US · Financial Servicesransomthegentlemen reclama a TopMark Funding · US · Financial Servicesransomthegentlemen reclama a Control Concepts Technology · US · Technologyransomchaos reclama a healthcarehighways.com · US · Healthcareransomgunra reclama a worldtube · KR · Technologyransomqilin reclama a WD Masonry & Concrete · US · Otherransomakira reclama a University SprinklerSystems · Manufacturingransomorova reclama a Tat Fung Textile Co., Ltd. · HK · Manufacturingransomorova reclama a Integrated Site Management · US · Professional Services
← Todos los CVEs
CVE Watch3 ago 2026

CVE-2026-15236

The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials o

CVSS

7.5

Alto

EPSS

0.2%

p6

KEV

Exploit Today

2

0-100

Publicado: 2 ago 2026 · Última mod.: 3 ago 2026 · CWE-200

EPSS · 30d
0.2%EPSS · 30 días0.2%
2026-08-022026-08-03
Descripción técnica

The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing the persistent access and refresh tokens to unauthenticated users and allowing long-term compromise of the linked account.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-69153
0PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting map’s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.1d
CVE-2026-673577.5 ALT
16.5%
5ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and achieve full server compromise.23h
CVE-2026-673438.8 ALT
22.2%
7ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in cleartext. Attackers can use the leaked token with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and execute administrative actions including user creation, database operations, and server shutdown.23h
CVE-2026-673395.3 MED
14.3%
4guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections.1d
CVE-2026-673227.5 ALT
18.4%
6GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking git clone. An attacker who controls the clone URL can embed $NAME or ${NAME} tokens that are expanded to the values of the hosting process's environment variables (e.g., AWS_SECRET_ACCESS_KEY or GITHUB_TOKEN). The resulting URL, now containing the secret, is transmitted over the network to an attacker-controlled host during the clone attempt, disclosing the secret.1d
CVE-2026-67320
22.8%
7axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configuration by creating a null-prototype object, but request interceptors run after the merge; a common immutable interceptor pattern such as {...config} or Object.assign({}, config) converts the hardened config back into a regular object. axios then dispatches that object without re-hardening it, and the Node HTTP adapter reads config.proxy through the prototype chain. If an attacker can pollute Object.prototype.proxy, affected requests can be routed through an attacker-controlled proxy. For plaintext HTTP requests, the proxy can observe Authorization headers, Basic auth from config.auth, method, absolute URL, Host, and request body, and can return its own response. This does not establish browser impact or HTTPS header/body disclosure under normal TLS validation. Affected versions are >=0.31.1 (fixed in 0.33.0) and >=1.15.2 (fixed in 1.18.0).1d