Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-20230

Publication date:
03/06/2026
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.<br /> <br /> This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root.<br /> Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root.<br /> Note: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.
Severity CVSS v4.0: Pending analysis
Last modification:
01/07/2026

CVE-2025-71313

Publication date:
03/06/2026
In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> PCI: endpoint: Add missing NULL check for alloc_workqueue()<br /> <br /> alloc_workqueue() can return NULL on memory allocation failure. Without<br /> proper error checking, this may lead to a NULL pointer dereference when<br /> queue_work() is later called with the NULL workqueue pointer in<br /> epf_ntb_epc_init().<br /> <br /> Add a NULL check immediately after alloc_workqueue() and return -ENOMEM on<br /> failure to prevent the driver from loading with an invalid workqueue<br /> pointer.
Severity CVSS v4.0: Pending analysis
Last modification:
09/06/2026

CVE-2025-71314

Publication date:
03/06/2026
In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> drm/panthor: Recover from panthor_gpu_flush_caches() failures<br /> <br /> We have seen a few cases where the whole memory subsystem is blocked<br /> and flush operations never complete. When that happens, we want to:<br /> <br /> - schedule a reset, so we can recover from this situation<br /> - in the reset path, we need to reset the pending_reqs so we can send<br /> new commands after the reset<br /> - if more panthor_gpu_flush_caches() operations are queued after<br /> the timeout, we skip them and return -EIO directly to avoid needless<br /> waits (the memory block won&amp;#39;t miraculously work again)<br /> <br /> Note that we drop the WARN_ON()s because these hangs can be triggered<br /> with buggy GPU jobs created by the UMD, and there&amp;#39;s no way we can<br /> prevent it. We do keep the error messages though.<br /> <br /> v2:<br /> - New patch<br /> <br /> v3:<br /> - Collect R-b<br /> - Explicitly mention the fact we dropped the WARN_ON()s in the commit<br /> message<br /> <br /> v4:<br /> - No changes
Severity CVSS v4.0: Pending analysis
Last modification:
09/06/2026

CVE-2026-20175

Publication date:
03/06/2026
A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks.<br /> <br /> This vulnerability is due to insufficient validation of user-supplied input for HTTP requests that are sent to an affected device. An attacker who has knowledge of the address of the affected device could exploit this vulnerability by persuading a user to click a crafted link that contains the affected device address. A successful exploit could allow the attacker to conduct browser-based attacks and execute arbitrary script code in the context of the affected interface or access sensitive information on the affected device.
Severity CVSS v4.0: Pending analysis
Last modification:
04/06/2026

CVE-2019-25720

Publication date:
03/06/2026
Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain a denial-of-service vulnerability in all software versions that allows unauthenticated attackers to reboot the monitor by sending a malformed network packet. Attackers can repeatedly send such malformed packets to disrupt patient monitoring until the device falls back to default configuration and loses network connectivity.
Severity CVSS v4.0: HIGH
Last modification:
17/06/2026

CVE-2026-6657

Publication date:
03/06/2026
A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used. The issue arises from the use of `re.match()` for validating the `Origin` header, which only anchors at the start of the string. This allows attacker-controlled domains such as `trusted.example.com.evil.com` to pass validation against patterns intended to match `trusted.example.com`. The vulnerability affects multiple locations in the codebase, including CORS headers, WebSocket connections, referer validation, and login redirects, potentially enabling phishing attacks, arbitrary code execution, and unauthorized access to sensitive API responses.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2026

CVE-2026-42321

Publication date:
03/06/2026
GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a technician can store an XSS payload in the asset locked tab. Upgrade to 10.0.25 or 11.0.7 to receive a patch.
Severity CVSS v4.0: HIGH
Last modification:
04/06/2026

CVE-2026-44281

Publication date:
03/06/2026
GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, an authenticated user with config READ permission can read a specific asset object. Upgrade to 11.0.7 or 10.0.25 to receive a patch.
Severity CVSS v4.0: HIGH
Last modification:
04/06/2026

CVE-2026-3276

Publication date:
03/06/2026
unicodedata.normalize() can take excessive CPU time when processing<br /> specially crafted Unicode input containing long runs of combining characters<br /> with alternating Canonical Combining Class values.<br /> This affects all normalization forms.
Severity CVSS v4.0: MEDIUM
Last modification:
16/06/2026

CVE-2026-42317

Publication date:
03/06/2026
GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, a technician can delete arbitrary files from the filesystem as long as the webserver has write rights on them. Upgrade to 10.0.25 or 11.0.7 to receive a patch.
Severity CVSS v4.0: HIGH
Last modification:
04/06/2026

CVE-2026-42318

Publication date:
03/06/2026
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.0.7, low privilege users with access to planning can delete any object in GLPI. Upgrade to 11.0.7 or 10.0.25 to receive a patch. As a workaround, disable delete rights for User&amp;#39;s planning.
Severity CVSS v4.0: HIGH
Last modification:
04/06/2026

CVE-2026-42320

Publication date:
03/06/2026
GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0.7, a technician can read arbitrary files inside the GLPI_DOC_DIR. Upgrade to 10.0.25 or 11.0.7 to receive a patch.
Severity CVSS v4.0: MEDIUM
Last modification:
04/06/2026