PULSE
EN VIVO85señales / 24h
FEED
ransomincransom reclama a takethehop.com · US · Hospitalityransomglobal secret group reclama a Park Manufacturing Corp. · US · Manufacturingransomexfilsquad reclama a Wesco International · US · Manufacturingransomgenesis reclama a Williams Accounting Professional · CA · Professional Servicesransomgenesis reclama a JJP Slip Forming Inc. · US · Manufacturingransomgenesis reclama a Building Envelope Systems · US · Manufacturingransomgenesis reclama a Westlake Realty Group, Inc. · US · Retail & E-Commerceransomgenesis reclama a Servonix Technologies · US · Not Foundransomgenesis reclama a Infinity Pipeline,Inc. · US · Energy & Utilitiesransomglobal secret group reclama a Hinduja Tech | BMW Group & Škoda Auto · IN · Manufacturingransomglobal secret group reclama a Pro-Tuff | Decals · US · Retail & E-Commerceransomdeadlock reclama a High Class Car Limo · US · Transportationransomanubis reclama a Eagle Crest Communities · US · Hospitalityransomglobal secret group reclama a Spergel · CA · Professional Servicesransomincransom reclama a takethehop.com · US · Hospitalityransomglobal secret group reclama a Park Manufacturing Corp. · US · Manufacturingransomexfilsquad reclama a Wesco International · US · Manufacturingransomgenesis reclama a Williams Accounting Professional · CA · Professional Servicesransomgenesis reclama a JJP Slip Forming Inc. · US · Manufacturingransomgenesis reclama a Building Envelope Systems · US · Manufacturingransomgenesis reclama a Westlake Realty Group, Inc. · US · Retail & E-Commerceransomgenesis reclama a Servonix Technologies · US · Not Foundransomgenesis reclama a Infinity Pipeline,Inc. · US · Energy & Utilitiesransomglobal secret group reclama a Hinduja Tech | BMW Group & Škoda Auto · IN · Manufacturingransomglobal secret group reclama a Pro-Tuff | Decals · US · Retail & E-Commerceransomdeadlock reclama a High Class Car Limo · US · Transportationransomanubis reclama a Eagle Crest Communities · US · Hospitalityransomglobal secret group reclama a Spergel · CA · Professional Services
← Todos los CVEs
CVE Watch23 jul 2026

CVE-2026-47910

Dreamweaver Desktop versions 21.7 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary file sys

CVSS

6.3

Medio

EPSS

0.1%

p4

KEV

Exploit Today

1

0-100

Publicado: 9 jun 2026 · Última mod.: 23 jul 2026 · CWE-863

EPSS · 30d
0.1%EPSS · 30 días0.1%
2026-06-302026-07-25
Descripción técnica

Dreamweaver Desktop versions 21.7 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-170393.1 BAJ
11.4%
3A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to be renewed without that realm's authorization.2d
CVE-2026-87898.1 ALT
13.0%
4The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary connection records from the `wp_ea_connections` table, disrupting the plugin's core booking functionality.2d
CVE-2026-157049.8 CRÍ
27.9%
8In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router. The shared router configuration used Chi's `middleware.StripSlashes`, so a request such as `GET /shells/` was dispatched to the registered `GET /shells` route. However, the ABAC middleware evaluated the original request path including the trailing slash. If ABAC route lookup did not find a matching slash-suffixed route, the request was passed onward and the router then stripped the slash and executed the protected handler without the intended ABAC authorization decision and without the expected ABAC query filters. An unauthenticated or unauthorized network attacker could append a trailing slash to protected API routes to reach handlers that should have been denied by ABAC policy. Depending on the exposed component, HTTP method, and deployed policy, this could allow unauthorized read, create, update, delete, or upload operations. The issue affects ABAC-enabled deployments of services that use the shared router and ABAC middleware, including AAS Repository, Submodel Repository, AAS Registry, Submodel Registry, Concept Description Repository, Discovery, AAS Environment upload, and related services. The issue is fixed in Eclipse BaSyx Go Components v1.0.1.2d
CVE-2026-59678
1.9%
1An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.3d
CVE-2026-130684.2 MED
4.6%
1An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongoing query operations for other users. The behavior stems from an authorization check that does not correctly scope privileges to the appropriate namespace.3d
CVE-2026-130676.3 MED
0.0%
0When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-list. This can result in unintended role assignments following MONGODB-X509 authentication. Affected scenarios require local access to the proxy Unix domain socket and a valid X.509 certificate issued by a trusted certificate authority.3d