Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-15548

Publication date:
13/07/2026
A security vulnerability has been detected in Shibby Tomato up to 1.28.0000. This vulnerability affects the function sub_407220 of the file /usr/sbin/httpd of the component DNS List Rendering. The manipulation leads to stack-based buffer overflow. The attack is possible to be carried out remotely. This project is superseded by FreshTomato.
Severity CVSS v4.0: HIGH
Last modification:
15/07/2026

CVE-2026-22093

Publication date:
13/07/2026
The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided by the server. This allows an attacker on the network path between the app and EVbee server to intercept and manipulate the communication between the app and server. The traffic is weakly encrypted using RC4 with a hardcoded key, which allows an attacker to gain access to the communication. Part of this communication involves access codes to charging stations.<br /> <br /> <br /> <br /> <br /> <br /> This issue affects EVbee Service: v1.4.101.00.
Severity CVSS v4.0: CRITICAL
Last modification:
13/07/2026

CVE-2026-14846

Publication date:
13/07/2026
In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of elements, caused by inadequate validation of the ‘Alias’ parameter in the ‘Update your address’ function. This flaw allows an attacker to inject malicious expressions that are executed when the information is exported using the ‘Get my data in CSV’ tool. Successful exploitation of this vulnerability could facilitate unauthorised access to the victim’s personal data.
Severity CVSS v4.0: MEDIUM
Last modification:
13/07/2026

CVE-2026-15557

Publication date:
13/07/2026
A weakness has been identified in waooAI waoowaoo up to 0.4.1. Affected by this vulnerability is the function getInternalTaskSession/getAuthSession/requireUserAuth/requireProjectAuth/requireProjectAuthLight in the library src/lib/api-auth.ts of the component Internal Task Header Handler. This manipulation of the argument x-internal-user-id request causes improper authentication. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity CVSS v4.0: MEDIUM
Last modification:
13/07/2026

CVE-2026-13014

Publication date:
13/07/2026
A vulnerability in Thales CERT "Suspicious" application =
Severity CVSS v4.0: CRITICAL
Last modification:
13/07/2026

CVE-2026-9571

Publication date:
13/07/2026
Mattermost versions 11.7.x
Severity CVSS v4.0: Pending analysis
Last modification:
15/07/2026

CVE-2026-9708

Publication date:
13/07/2026
Mattermost versions 11.7.x
Severity CVSS v4.0: Pending analysis
Last modification:
13/07/2026

CVE-2026-9597

Publication date:
13/07/2026
Mattermost versions 11.7.x
Severity CVSS v4.0: Pending analysis
Last modification:
13/07/2026

CVE-2026-15545

Publication date:
13/07/2026
A vulnerability was identified in Shibby Tomato up to 1.28.0000. Affected by this vulnerability is the function main of the file www/apcupsd/tomatodata.cgi of the component apcupsd. Such manipulation leads to out-of-bounds write. The attack may be launched remotely. The exploit is publicly available and might be used. This project is superseded by FreshTomato.
Severity CVSS v4.0: HIGH
Last modification:
13/07/2026

CVE-2026-15547

Publication date:
13/07/2026
A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048 of the component CIFS Mount Handler. Executing a manipulation of the argument cifs1/cifs2 can lead to os command injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. This project is superseded by FreshTomato.
Severity CVSS v4.0: LOW
Last modification:
13/07/2026

CVE-2026-15574

Publication date:
13/07/2026
A flaw was found in the vllm-orchestrator-gateway component. The system&amp;#39;s production binary logs all incoming authorization headers and full chat payloads, which may contain personally identifiable information (PII) and secrets, to persistent logs. This sensitive data, including bearer tokens and chat content, can be accessed by any user with logging privileges. This vulnerability leads to information disclosure, potentially allowing an attacker to harvest credentials and sensitive conversation content.
Severity CVSS v4.0: Pending analysis
Last modification:
13/07/2026

CVE-2026-15546

Publication date:
13/07/2026
A security flaw has been discovered in Shibby Tomato up to 1.28.0000. Affected by this issue is the function sub_2D568 of the component start_jffs2. Performing a manipulation of the argument jffs2_exec results in os command injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. This project is superseded by FreshTomato.
Severity CVSS v4.0: LOW
Last modification:
13/07/2026