Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-6881

Publication date:
28/07/2026
A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field.<br /> <br /> <br /> <br /> This issue affects Advance Web: all versions; Legacy Advance: all versions.<br /> <br /> <br /> <br /> Ellucian CRM Advance is not impacted.
Severity CVSS v4.0: CRITICAL
Last modification:
29/07/2026

CVE-2026-56722

Publication date:
28/07/2026
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypass this restriction by embedding a target file path inside an SVG image delivered through a  data:  URI, because dompdf processes the SVG twice and the second pass does not enforce the same protections as the first. When rendering, dompdf hands the SVG to the separate  php-svg-lib  library with external references forced on, and that library has no knowledge of the chroot directory, blocks only the  phar://  scheme, and ultimately reads the referenced file with no path or protocol validation. This lets an external, unauthenticated attacker read arbitrary image files from the server&amp;#39;s file system in the default configuration. This issue has been fixed in version 3.16.
Severity CVSS v4.0: MEDIUM
Last modification:
04/08/2026

CVE-2026-16581

Publication date:
28/07/2026
In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls.
Severity CVSS v4.0: MEDIUM
Last modification:
30/07/2026

CVE-2026-49447

Publication date:
28/07/2026
Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. In 0.22.18, `GET /cosmos/api/constellation/public-devices` discloses Constellation device metadata to a requester that supplies any non-empty Authorization header. The handler strips the string Bearer from the header but never validates the resulting token and never uses it in the database query. This vulnerability is fixed in 0.22.19.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-15057

Publication date:
28/07/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2026

CVE-2026-14996

Publication date:
28/07/2026
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2026

CVE-2026-15064

Publication date:
28/07/2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens.
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2026

CVE-2026-15280

Publication date:
28/07/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability in the collective routing mechanism.
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2026

CVE-2026-15328

Publication date:
28/07/2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling.
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2026

CVE-2026-14981

Publication date:
28/07/2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2026

CVE-2026-15325

Publication date:
28/07/2026
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling due to improper handling of TRACE requests.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2026

CVE-2026-14976

Publication date:
28/07/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled.
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2026