Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-33582

Publication date:
09/06/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.<br /> <br /> This issue affects Apache Answer: through 2.0.0.<br /> <br /> A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash.<br /> Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-34031

Publication date:
09/06/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.<br /> <br /> This issue affects Apache Answer: through 2.0.0.<br /> <br /> The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers.<br /> Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-34033

Publication date:
09/06/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer.<br /> <br /> This issue affects Apache Answer: through 2.0.0.<br /> <br /> User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users.<br /> Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-34905

Publication date:
09/06/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer.<br /> <br /> This issue affects Apache Answer: through 2.0.0.<br /> <br /> The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history.<br /> Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-11616

Publication date:
09/06/2026
The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 2.3.28. This is due to the ajax_ayi_action() handler only applying strip_tags(esc_sql()) — with no allow-list — to the attacker-controlled $_POST[&amp;#39;type&amp;#39;] and $_POST[&amp;#39;postid&amp;#39;] values before forwarding them to update_ayi_data(), which calls update_user_meta($current_user-&gt;ID, $rsvp_args[&amp;#39;type&amp;#39;], $posts). By passing type=wp_capabilities and postid=administrator, an attacker writes [&amp;#39;subscriber&amp;#39;=&gt;true,&amp;#39;administrator&amp;#39;=&gt;&amp;#39;administrator&amp;#39;] into their own wp_capabilities user meta; WP_User::get_role_caps() then treats the &amp;#39;administrator&amp;#39; array key as an active role on the next request. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to Administrator.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-25688

Publication date:
09/06/2026
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer.<br /> <br /> This issue affects Apache Answer: through 2.0.0.<br /> <br /> AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed.<br /> Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-25699

Publication date:
09/06/2026
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer.<br /> <br /> This issue affects Apache Answer: through 2.0.0.<br /> <br /> Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history.<br /> Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2009-10007

Publication date:
09/06/2026
Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks.<br /> <br /> Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a session id cookie can use this to impersonate the victim.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2026

CVE-2026-5068

Publication date:
09/06/2026
A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE CoC SDU reassembly. When the application enables segmentation (via chan_ops.alloc_buf) and the chosen RX pool has a user_data_size smaller than 2 bytes, the segmentation counter stored in the net_buf user_data area is written out of bounds in l2cap_chan_le_recv_seg (subsys/bluetooth/host/l2cap.c). The observed effects are an AddressSanitizer abort and, without ASan, heap corruption / fatal error.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-9698

Publication date:
09/06/2026
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.<br /> <br /> Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit.<br /> <br /> Attackers that can influence the error text in an application can trigger a buffer overflow.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-41981

Publication date:
09/06/2026
Out-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-41982

Publication date:
09/06/2026
Race condition vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026