Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-34692

Publication date:
09/06/2026
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-35188

Publication date:
09/06/2026
Issue summary: A malicious server can exploit TLS OCSP stapling by delivering<br /> a crafted response through the status_request extension, triggering a<br /> double-free in the client&amp;#39;s certificate verification path.<br /> <br /> Impact summary: Successful exploitation allows an attacker to corrupt heap<br /> memory via a double-free, potentially leading to a Denial of Service or<br /> possibly an attacker controlled code execution or other undefined behavior.<br /> <br /> If OCSP stapling is enabled and the TLS client connects to a malicious server,<br /> a crafted OCSP stapled response can trigger a double free in the TLS client<br /> when the stapled response is checked.<br /> <br /> The OCSP stapling is not enabled by default. Reliable code execution<br /> through a double-free is technically complex and highly environment-dependent<br /> but the Denial of Service impact is straightforward to achieve, warranting<br /> Moderate severity.<br /> <br /> No FIPS modules are affected by this issue as the affected code is outside<br /> the OpenSSL FIPS module boundary.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-38615

Publication date:
09/06/2026
DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-3088

Publication date:
09/06/2026
Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.
Severity CVSS v4.0: MEDIUM
Last modification:
23/07/2026

CVE-2026-40371

Publication date:
09/06/2026
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-33113

Publication date:
09/06/2026
Improper neutralization of input during web page generation (&amp;#39;cross-site scripting&amp;#39;) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-33828

Publication date:
09/06/2026
Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-34180

Publication date:
09/06/2026
Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive<br /> element whose content exceeds 2 gigabytes in length may cause a heap buffer<br /> over-read on 64-bit Unix and Unix-like platforms.<br /> <br /> Impact summary: The heap buffer over-read may crash the application (Denial of<br /> Service) or to load into the decoded ASN.1 object contents of memory beyond the<br /> end of the input buffer. More typically such ASN.1 elements would instead be<br /> truncated.<br /> <br /> An integer truncation in OpenSSL&amp;#39;s ASN.1 decoder causes the content length of<br /> an ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the<br /> worst case the truncated length is treated as a request to scan the binary<br /> content for a terminating zero byte, possibly causing OpenSSL to read either<br /> less than or beyond the end of the allocated buffer.<br /> <br /> Applications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or<br /> any other d2i_* decoding function are affected. OpenSSL&amp;#39;s own command-line<br /> tools are not vulnerable, as data read through the BIO layer is checked before<br /> it reaches the affected code. The issue only affects 64-bit Unix and Unix-like<br /> platforms; 32-bit platforms and 64-bit Windows are not affected.<br /> <br /> The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue,<br /> as the affected code is outside the OpenSSL FIPS module boundary.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-34181

Publication date:
09/06/2026
Issue Summary: The PKCS#12 file processing fails to perform sufficient input<br /> validation for files that use Password-Based Message Authentication Code 1<br /> (PBMAC1) integrity mechanism allowing a certificate and private key forgery.<br /> <br /> Impact Summary: An attacker impersonating a user can cause a service reading<br /> PKCS#12 files to accept forged certificates and private keys with a 1 in 256<br /> probability.<br /> <br /> If a service accepting PKCS#12 files is using passwords for authenticating<br /> the received files, the attacker can create unencrypted PKCS#12 files that<br /> use PBMAC1 authentication that specifies an HMAC key of only one byte, allowing<br /> them to craft a file that will be accepted with a 1 in 256 probability.<br /> That would then cause the service to accept a certificate and private key<br /> controlled by the attacker.<br /> <br /> The FIPS modules are not affected by this issue, as the affected code is<br /> outside the OpenSSL FIPS module boundary.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-34182

Publication date:
09/06/2026
Issue Summary: Cryptographic Message Services (CMS) processing fails to perform<br /> sufficient input validation on the cipher and tag length fields of<br /> AuthEnvelopedData containers, leading to various potential compromises.<br /> <br /> Impact Summary: Attackers making use of these vulnerabilities may achieve<br /> key-equivalent functionality for a given CMS recipient and/or bypass integrity<br /> validation for a given message.<br /> <br /> In one use case, an attacker may send a CMS message containing<br /> AuthEnvelopedData with the cipher specified as a non-AEAD cipher. OpenSSL<br /> erroneously allows this selection, and attempts to decrypt and validate the<br /> message.<br /> <br /> An on-path attacker who captures one legitimate AES-GCM AuthEnvelopedData<br /> addressed to the victim can re-emit it with the recipientInfos set left<br /> byte-for-byte intact, so the victim&amp;#39;s private key still unwraps the genuine CEK<br /> (the content-encryption key), but with the inner OID rewritten to AES-256-OFB<br /> (Output Feedback Mode, an unauthenticated keystream mode) and with an<br /> attacker-chosen IV and ciphertext. The victim initializes AES-256-OFB under the<br /> real CEK, never consults the MAC field, and CMS_decrypt() returns success.<br /> <br /> If the application under attack responds to the attacker with any indicator<br /> showing success or failure of the decryption effort, it is possible for the<br /> attacker to use this as an oracle to obtain key equivalent functionality for the<br /> CEK used for the chosen recipient of the message.<br /> <br /> In another use case, an attacker can reduce the tag length of the chosen AEAD<br /> cipher for a given AuthEnvelopedData container to be a single byte long,<br /> allowing an attacker to brute force CMS decryption, producing an integrity<br /> bypass for applications that trust CMS_decrypt() to reject modified content.<br /> <br /> The FIPS modules are not affected by this issue.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-26142

Publication date:
09/06/2026
Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-28301

Publication date:
09/06/2026
A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended website.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026