Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-43625

Publication date:
01/06/2026
CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network attackers to intercept imported browser session cookies by exploiting improper redirect handling for Amp and Ollama provider sessions. Attackers can position themselves on the network path to receive cleartext HTTP requests carrying imported session cookies when a provider-controlled redirect target issues a redirect to a cleartext HTTP endpoint within the same provider domain.
Severity CVSS v4.0: HIGH
Last modification:
22/07/2026

CVE-2026-43958

Publication date:
01/06/2026
A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a stack-based buffer overflow by sending an oversized CREATE request. This vulnerability can lead to a denial of service by crashing the daemon or potentially allow for arbitrary code execution, impacting the integrity and confidentiality of data.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-43623

Publication date:
01/06/2026
microtar through 0.1.0 contains a stack-based buffer overflow vulnerability in the raw_to_header() function in src/microtar.c that allows attackers to corrupt adjacent stack memory by supplying a crafted TAR archive with non-null-terminated name or linkname fields. The function uses strcpy() to copy 100-byte ustar format fields that lack null terminators, causing writes of up to 355 bytes into a 100-byte destination buffer when mtar_open(), mtar_find(), or mtar_read_header() process attacker-supplied TAR archives.
Severity CVSS v4.0: HIGH
Last modification:
22/07/2026

CVE-2026-43624

Publication date:
01/06/2026
F5-TTS through version 1.1.20 contains a path traversal vulnerability in the finetune Gradio handlers that allows unauthenticated attackers to write arbitrary files by passing unsanitized user-supplied project names directly to os.path.join() without validating the resulting path stays within the intended base directory. Attackers can supply absolute path arguments such as /tmp/EVIL to override the base directory entirely and create arbitrary directories with attacker-controlled JSON content at any filesystem path writable by the server process.
Severity CVSS v4.0: HIGH
Last modification:
22/07/2026

CVE-2026-40989

Publication date:
01/06/2026
Under infinite recursion in the routing layer, request-handling can cause OOM error.<br /> <br /> Affected Spring Products and Versions:<br /> Spring Cloud Function 3.2.x: versions prior to 3.2.16<br /> Spring Cloud Function 4.1.x: versions prior to 4.1.10<br /> Spring Cloud Function 4.2.x: versions prior to 4.2.6<br /> Spring Cloud Function 4.3.x: versions prior to 4.3.3<br /> Spring Cloud Function 5.0.x: versions prior to 5.0.2<br /> Older, unsupported versions are also affected.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-40990

Publication date:
01/06/2026
OOM error is possible while attempting to add infinite amount of functions to Function Registry.<br /> <br /> Affected Spring Products and Versions:<br /> Spring Cloud Function 3.2.x: versions prior to 3.2.16<br /> Spring Cloud Function 4.1.x: versions prior to 4.1.10<br /> Spring Cloud Function 4.2.x: versions prior to 4.2.6<br /> Spring Cloud Function 4.3.x: versions prior to 4.3.3<br /> Spring Cloud Function 5.0.x: versions prior to 5.0.2<br /> Older, unsupported versions are also affected.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-41013

Publication date:
01/06/2026
Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the mount-option allowlist, enabling privilege escalation and security control bypass on multi-tenant Diego cells.<br /> <br /> Affected versions:<br /> smb-volume-release: All versions prior to v3.60.0<br /> CF Deployment: All versions prior to v56.0.0
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-37226

Publication date:
01/06/2026
FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2 Node. The lookup function returns NULL, which is enforced by assert() in Debug builds (SIGABRT) and dereferenced in Release builds (SIGSEGV). A remote unauthenticated attacker can crash the iApp process (port 36422) by sending a subscription request with an arbitrary global_e2_node_id.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-37228

Publication date:
01/06/2026
FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c). The function allocates a fixed 32KB receive buffer and enforces assert(rc = 32,768 bytes to crash the near-RT RIC, iApp, E2 Agent, or xApp process via SIGABRT. No valid E2AP PDU is required. All four SCTP endpoint types (ports 36421 and 36422) share this vulnerable code path. In Release builds (NDEBUG), the stripped assertion leads to a signed-to-unsigned integer overflow and potential out-of-bounds read.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-37229

Publication date:
01/06/2026
FlexRIC v2.0.0 contains a reachable assertion in e2ap_create_pdu() triggered when ASN.1 PER decoding fails. A remote unauthenticated attacker can send any non-PER byte sequence (e.g., a single 0x00 byte) over SCTP to the near-RT RIC (port 36421) or iApp (port 36422) to crash the process via SIGABRT. The assertion is reached before any protocol-level validation occurs. All three E2AP protocol versions (v1.01, v2.03, v3.01) are affected.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-37230

Publication date:
01/06/2026
FlexRIC v2.0.0 crashes when the near-RT RIC receives a RIC_INDICATION message with a ran_func_id that does not exist in its registry. The lookup returns NULL, triggering assert() in Debug builds (SIGABRT) or NULL pointer dereference in Release builds (SIGSEGV). A remote unauthenticated attacker can crash the near-RT RIC (port 36421) by sending a crafted RIC_INDICATION with an arbitrary ran_func_id value.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-37231

Publication date:
01/06/2026
FlexRIC v2.0.0 uses a uint16_t counter for xapp_id assignment but stores the value in uint32_t message fields. After 65,530+ E42_SETUP_REQUESTs, the 16-bit counter wraps around and produces duplicate xapp_ids. The iApp (port 36422) crashes when attempting to register a duplicate ID in its internal data structure. A remote attacker can trigger this by repeatedly connecting and requesting new xApp registrations.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026