Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-32193

Publication date:
09/06/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-22926

Publication date:
09/06/2026
Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-24180

Publication date:
09/06/2026
NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-24181

Publication date:
09/06/2026
NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-0419

Publication date:
09/06/2026
Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local WiFi Networks to execute operating system commands. NETGEAR JR6150 has reached End-of-Support phase as of 2018 , and no <br /> further security updates are planned. NETGEAR strongly recommends <br /> replacing these devices with newer NETGEAR models to ensure continued <br /> security support and updates.<br /> <br /> <br /> <br /> This vulnerability has been identified through firmware emulation in a controlled research environment and has not been verified on production hardware.
Severity CVSS v4.0: MEDIUM
Last modification:
23/07/2026

CVE-2026-0420

Publication date:
09/06/2026
An improper implementation of TLS certificate validation vulnerability found in NETGEAR&amp;#39;s ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product&amp;#39;s confidentiality. This vulnerability affects the listed NETGEAR models.
Severity CVSS v4.0: MEDIUM
Last modification:
23/07/2026

CVE-2026-0417

Publication date:
09/06/2026
Insufficient input validation vulnerability in the listed NETGEAR devices allows<br /> authenticated administrators connected to the local network to tamper with<br /> the router&amp;#39;s integrity.
Severity CVSS v4.0: MEDIUM
Last modification:
23/07/2026

CVE-2026-0418

Publication date:
09/06/2026
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network<br /> to tamper with the system.
Severity CVSS v4.0: MEDIUM
Last modification:
23/07/2026

CVE-2026-0415

Publication date:
09/06/2026
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
Severity CVSS v4.0: MEDIUM
Last modification:
23/07/2026

CVE-2026-0416

Publication date:
09/06/2026
An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to submit crafted input that bypasses intended management interface restrictions, resulting in unauthorized modification of protected router software or functionality.
Severity CVSS v4.0: MEDIUM
Last modification:
23/07/2026

CVE-2026-0409

Publication date:
09/06/2026
A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the router and the Internet to run commands on your device when the device administrator performs certain specific management actions. This issue affects NETGEAR Orbi 370 series devices before V12.1.2.7.
Severity CVSS v4.0: MEDIUM
Last modification:
23/07/2026

CVE-2026-0410

Publication date:
09/06/2026
Authenticated administrators connected to the local network can gain <br /> elevated access to the router and make unauthorized changes to router <br /> software and functionality.
Severity CVSS v4.0: LOW
Last modification:
23/07/2026