Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-15659

Publication date:
15/06/2026
Contributor Cross Site Scripting (XSS) in Elizaibots
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2026

CVE-2026-10634

Publication date:
15/06/2026
Zephyr&amp;#39;s native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) using the SYS_SLIST_FOR_EACH_CONTAINER_SAFE macro, which caches a pointer to the next list node. Prior to this fix the function released tcp_lock while invoking the per-connection callback and re-acquired it afterwards.<br /> <br /> During that window a concurrent tcp_conn_release(), running on the dedicated TCP work-queue thread when a connection&amp;#39;s reference count drops to zero (e.g. a remote peer closing or resetting the connection), can remove and k_mem_slab_free() the cached next connection. When the iterator advances it dereferences the freed (and possibly reallocated) slab memory — a use-after-free that can crash the system (denial of service) and, if the slot has been reused, cause the callback to operate on an attacker-influenced object (potential information disclosure or further fault).<br /> <br /> net_tcp_foreach() is reached in production via the net conn network shell command and via net_tcp_close_all_for_iface() on interface-down; the freeing side is driven by ordinary TCP traffic.<br /> <br /> The fix moves the connection/context teardown in tcp_conn_release() inside the tcp_lock critical section and keeps tcp_lock held across the callback in net_tcp_foreach(). The defect was introduced with the modern (TCP2) stack in 2020 and affects releases up to and including v4.4.0.
Severity CVSS v4.0: Pending analysis
Last modification:
14/07/2026

CVE-2025-15658

Publication date:
15/06/2026
Administrator Cross Site Scripting (XSS) in WP Emmet
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2026

CVE-2026-5230

Publication date:
15/06/2026
Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library allows Exploiting Incorrectly Configured Access Control Security Levels.<br /> <br /> This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2026

CVE-2026-5233

Publication date:
15/06/2026
Improper Control of Interaction Frequency vulnerability in MIA Technology Inc. Pizzy Library allows Flooding.<br /> <br /> This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2026

CVE-2026-5242

Publication date:
15/06/2026
Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy Library allows Code Injection.<br /> <br /> This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2026

CVE-2026-5079

Publication date:
15/06/2026
Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form data. The append-field dependency parses bracket notation in field names with no limit on nesting depth, allowing an attacker to force allocation of deeply nested object structures that consume CPU and memory. A single HTTP request with a crafted multipart body is sufficient to exploit this.<br /> <br /> Patches: Users should upgrade to multer 2.2.0 (2.x line) or 3.0.0-alpha.2 (3.x prerelease) and configure the new limits.fieldNestingDepth option to the minimum depth their application requires.<br /> <br /> Workarounds: Set limits.fields to a reasonable value to reduce the number of fields an attacker can send per request. This does not fully mitigate the issue but limits the impact.
Severity CVSS v4.0: Pending analysis
Last modification:
16/06/2026

CVE-2026-6517

Publication date:
15/06/2026
Mattermost Desktop App versions
Severity CVSS v4.0: Pending analysis
Last modification:
16/06/2026

CVE-2026-52704

Publication date:
15/06/2026
Improper Control of Generation of Code (&amp;#39;Code Injection&amp;#39;) vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion.<br /> <br /> This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0.8.
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2026

CVE-2026-48969

Publication date:
15/06/2026
Subscriber Broken Access Control in Really Simple SSL
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2026

CVE-2026-49062

Publication date:
15/06/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Exploitation.<br /> <br /> This issue affects Faust.Js: from n/a through 1.8.7.
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2026

CVE-2026-49064

Publication date:
15/06/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Data.<br /> <br /> This issue affects GetPaid: from n/a through 2.8.49.
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2026