Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-47851

Publication date:
27/08/2026
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread.<br /> Spring AI 2.0.0<br /> Spring AI 1.1.0 - 1.1.8<br /> Spring AI 1.0.0 - 1.0.9
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-47852

Publication date:
27/08/2026
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file.<br /> Spring AI 2.0.0<br /> Spring AI 1.1.0 - 1.1.8<br /> Spring AI 1.0.0 - 1.0.9
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-47856

Publication date:
27/08/2026
Spring Integration&amp;#39;s JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that header value to a class with ClassUtils.forName and no type/package allow-list.<br /> Spring Integration 7.1.0<br /> Spring Integration 7.0.0 - 7.0.5<br /> Spring Integration 6.5.0 - 6.5.10<br /> Spring Integration 6.4.0 - 6.4.12<br /> Spring Integration 5.5.21 and earlier
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-47857

Publication date:
27/08/2026
In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition.<br /> Reactor Core 3.8.0 - 3.8.6<br /> Reactor Core 3.5.0 - 3.7.19<br /> Reactor Core 3.4.41 and earlier
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-47859

Publication date:
27/08/2026
RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frames, trusts the sender-supplied octet count of an octet-counted frame and allocates a byte array of exactly that size with no upper bound.<br /> Spring Integration 7.1.0<br /> Spring Integration 7.0.0 - 7.0.5<br /> Spring Integration 6.5.0 - 6.5.10<br /> Spring Integration 6.4.0 - 6.4.12<br /> Spring Integration 5.5.21 and earlier
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-47845

Publication date:
27/08/2026
In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. In order for this to happen, the application must be configured to use HAProxy Protocol.<br /> Reactor Netty 1.3.0 - 1.3.6<br /> Reactor Netty 1.1.0 - 1.2.18<br /> Reactor Netty 1.0.52 and earlier
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-47850

Publication date:
27/08/2026
Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP PUT against an immutable target type.<br /> Spring Data REST 5.1.0<br /> Spring Data REST 5.0.0 - 5.0.6<br /> Spring Data REST 4.5.0 - 4.5.12<br /> Spring Data REST 4.0.0 - 4.4.15<br /> Spring Data REST 3.7.20 and earlier
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-80158

Publication date:
26/08/2026
A flaw was found in the ipa_getkeytab module of the community.general<br /> Ansible collection. The module&amp;#39;s bind_pw parameter, used to supply the LDAP simple-bind password when retrieving a Kerberos keytab, is not declared with no_log, unlike the sibling password parameter in the same module. As a consequence, the supplied IPA/LDAP bind password is recorded in cleartext in the managed host&amp;#39;s system journal/syslog (the module&amp;#39;s "Invoked with" record), is included in the module&amp;#39;s return values and verbose (-v) output, and is displayed in Automation Controller / AWX job output. The password is additionally passed on the command line to the ipa-getkeytab helper (as --bindpw ), exposing it in the process list to local users while the command runs. An attacker able to read these logs, job output, or the process table can obtain the directory bind credential, potentially compromising the accounts and objects that credential can access.
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-81203

Publication date:
26/08/2026
A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity CVSS v4.0: MEDIUM
Last modification:
26/08/2026

CVE-2026-75340

Publication date:
26/08/2026
The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF).
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-75330

Publication date:
26/08/2026
The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-75332

Publication date:
26/08/2026
Zyplayer-Doc
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026