Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-33760

Publication date:
23/06/2026
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monitor router exposes 7 endpoints that perform read, write, and delete operations on user-owned resources — messages, sessions, build artifacts, and LLM transaction logs — without verifying that the authenticated requester owns the targeted resource. Any authenticated user can read, modify, rename, or permanently delete another user's data by supplying the target's resource ID or flow_id. This is a classic IDOR/BOLA vulnerability. Notably, the same source file (monitor.py) contains one correctly-implemented endpoint that uses an ownership check, demonstrating the correct pattern was known but inconsistently applied. This vulnerability is fixed in 1.9.0.
Severity CVSS v4.0: Pending analysis
Last modification:
26/06/2026

CVE-2026-12958

Publication date:
23/06/2026
Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary.<br /> <br /> <br /> <br /> To remediate this issue, users should upgrade to version 1.69.0 or higher.
Severity CVSS v4.0: HIGH
Last modification:
23/06/2026

CVE-2026-12957

Publication date:
23/06/2026
Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the user to trust the workspace when prompted.<br /> <br /> <br /> <br /> To remediate this issue, users should upgrade to Language Servers for AWS version 1.65.0 or higher.
Severity CVSS v4.0: HIGH
Last modification:
23/06/2026

CVE-2026-11940

Publication date:
23/06/2026
tarfile.extractall() with the &amp;#39;data&amp;#39; or &amp;#39;tar&amp;#39;<br /> filter could be bypassed by a crafted archive where a hardlink <br /> references a symlink stored at a deeper name than the hardlink itself.  <br /> The extraction fallback validated the symlink at it&amp;#39;s archived location <br /> but recreated it at the hardlink&amp;#39;s shallower<br /> path, letting a relative<br /> target the filter judged contained escape the destination directory.  <br /> This allowed a malicious tar archive to create a symlink pointing <br /> outside the destination, enabling out-of-destination file reads or <br /> writes. This was an incomplete fix of CVE-2025-4330.
Severity CVSS v4.0: HIGH
Last modification:
23/07/2026

CVE-2025-61022

Publication date:
23/06/2026
An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
Severity CVSS v4.0: Pending analysis
Last modification:
23/06/2026

CVE-2025-61025

Publication date:
23/06/2026
An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
Severity CVSS v4.0: Pending analysis
Last modification:
23/06/2026

CVE-2025-61020

Publication date:
23/06/2026
An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
Severity CVSS v4.0: Pending analysis
Last modification:
15/07/2026

CVE-2025-61023

Publication date:
23/06/2026
An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
Severity CVSS v4.0: Pending analysis
Last modification:
15/07/2026

CVE-2025-61028

Publication date:
23/06/2026
An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
Severity CVSS v4.0: Pending analysis
Last modification:
15/07/2026

CVE-2025-61018

Publication date:
23/06/2026
An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
Severity CVSS v4.0: Pending analysis
Last modification:
15/07/2026

CVE-2026-56695

Publication date:
23/06/2026
OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing private prompts, credentials, tool output, and file paths via shared gateway channels.
Severity CVSS v4.0: HIGH
Last modification:
24/06/2026

CVE-2026-56696

Publication date:
23/06/2026
OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project context files. Admitted remote attackers can inject malicious content into .openharness/issue.md and .openharness/pr_comments.md files, which are subsequently injected into runtime system prompts, persistently influencing local agent behavior.
Severity CVSS v4.0: MEDIUM
Last modification:
23/06/2026