Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-45320

Publication date:
15/07/2026
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase dashboard SQL variables such as ${deptId} are processed by SqlparserUtils.transFilter(), whose final branch returns raw user input for non-in and non-between operators before SubstitutedSql.replace("${var}", value) splices it into dashboard SQL, allowing authenticated users who can view a dashboard to inject SQL against integrated datasources. This issue is fixed in version 2.10.23
Severity CVSS v4.0: HIGH
Last modification:
17/07/2026

CVE-2026-40956

Publication date:
15/07/2026
CVE-2026-40956<br /> is a memory disclosure vulnerability in Secure Access client versions prior to 14.55.<br /> Attackers with intimate knowledge of and total control over the tunnel protocol<br /> can cause a small amount of random memory to leak.
Severity CVSS v4.0: LOW
Last modification:
16/07/2026

CVE-2026-40957

Publication date:
15/07/2026
o  <br /> CVE-2026-40957 is a frameable content<br /> vulnerability in the Secure Access server login page prior to 14.55. Attackers<br /> with control of a malicious web site could use it to potentially steal<br /> credentials from an unwary administrator.
Severity CVSS v4.0: MEDIUM
Last modification:
16/07/2026

CVE-2026-40958

Publication date:
15/07/2026
CVE-2026-40958<br /> is a input validation error in Secure Access clients prior to 14.55. Attackers<br /> with intimate knowledge of and total control over the tunnel protocol can<br /> create a non-persistent DoS against their client.
Severity CVSS v4.0: LOW
Last modification:
16/07/2026

CVE-2026-40955

Publication date:
15/07/2026
CVE-2026-40955 is an integer underflow<br /> vulnerability in the traffic parsing function of Secure Access clients prior to<br /> 14.55. Attackers with intimate knowledge of and total control over the tunnel<br /> protocol can create a non-persistent DoS against their client.
Severity CVSS v4.0: LOW
Last modification:
16/07/2026

CVE-2026-40953

Publication date:
15/07/2026
CVE-2026-40953 is a heap overflow in the<br /> certificate parsing function of Secure Access clients prior to 14.55. Attackers<br /> with local access and administrator permissions can create a denial of service<br /> attack against the client over which they have control.
Severity CVSS v4.0: MEDIUM
Last modification:
16/07/2026

CVE-2026-40954

Publication date:
15/07/2026
CVE-2026-40954<br /> is an integer underflow vulnerability in the traffic parsing function of Secure<br /> Access clients prior to 14.55. Attackers with intimate knowledge of and total<br /> control over the tunnel protocol can create a non-persistent DoS against their<br /> client
Severity CVSS v4.0: LOW
Last modification:
16/07/2026

CVE-2026-40952

Publication date:
15/07/2026
CVE-2026-40952 is a privilege misconfiguration<br /> in the Secure Access installer for the Windows client and server prior to<br /> version 14.55. Attackers with local access to the client or server can use it<br /> to elevate privileges to Administrator when Secure Access is installed in a<br /> non-default location.
Severity CVSS v4.0: HIGH
Last modification:
16/07/2026

CVE-2026-33443

Publication date:
15/07/2026
CVE-2026-33443 is a memory management error in<br /> Secure Access servers prior to 14.55. Attackers with an intimate knowledge of<br /> and total control over the tunnel protocol can create a persistent DoS against<br /> the server.
Severity CVSS v4.0: HIGH
Last modification:
16/07/2026

CVE-2026-62353

Publication date:
15/07/2026
TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailing backslash in a SQL string literal such as &amp;#39;abc\ and read one byte beyond the null terminator, allowing an authenticated user who can submit SQL queries to crash the server and possibly leak adjacent memory. This issue is fixed in version 3.4.1.14.
Severity CVSS v4.0: Pending analysis
Last modification:
15/07/2026

CVE-2026-62355

Publication date:
15/07/2026
TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Reader admin_user on a TDengine Cloud DB instance could run create udf even though standard users should have read-only permissions for non-database objects and show dnodes and create user were denied. This issue is fixed in version 3.4.1.15.
Severity CVSS v4.0: Pending analysis
Last modification:
15/07/2026

CVE-2026-62947

Publication date:
15/07/2026
OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller&amp;#39;s ubus session file ACL before canonicalization, and rpcd session.c uses fnmatch() without FNM_PATHNAME, allowing traversal such as an allowed wildcard prefix followed by ../ to read root-readable files including /etc/shadow. This vulnerability is fixed in 25.12.5.
Severity CVSS v4.0: Pending analysis
Last modification:
15/07/2026