Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-78002

Publication date:
27/08/2026
A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement, causing memory corruption. Successful exploitation can lead to a denial of service (DoS) for the affected system.
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-75871

Publication date:
27/08/2026
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to redirect outbound model requests to an externally-controlled endpoint via a crafted inline flow configuration that overrides the HTTP Host header, resulting in disclosure of Google Cloud Vertex cloud service credentials and private signing keys.
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-75573

Publication date:
27/08/2026
In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured command output and encrypted key file may use the disclosed password to access the associated TLS client key.
Severity CVSS v4.0: MEDIUM
Last modification:
27/08/2026

CVE-2026-75357

Publication date:
27/08/2026
An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili-bridge.js components.
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-75159

Publication date:
27/08/2026
An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication exchange encounters a specific GSSAPI error-handling condition. This can interrupt BI Connector availability until the process restarts.
Severity CVSS v4.0: HIGH
Last modification:
27/08/2026

CVE-2026-71401

Publication date:
27/08/2026
An integer underflow was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capture.c does not verify that the IP total length field (ip_len) is at least as large as the IP header length (ihl) before subtracting the header length. An unauthenticated attacker on the same network can thereby trigger an out-of-bounds read past the receive buffer in the wicked DHCPv4 client (wickedd-dhcp4), which can crash the daemon depending on the process memory layout. No information disclosure has been demonstrated. This issue affects wicked up to and including version 0.6.80.
Severity CVSS v4.0: MEDIUM
Last modification:
27/08/2026

CVE-2026-71402

Publication date:
27/08/2026
An out-of-bounds read was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capture.c reports the IP total length as the payload length instead of the length of the remaining UDP payload. Consequently, the DHCP option walker in the DHCPv4 client (wickedd-dhcp4) reads up to ihl + 8 bytes — at most 68 bytes — past the end of the 1500-byte packet receive buffer. An unauthenticated attacker on the same network who sends a crafted DHCP/UDP packet can make the client parse adjacent heap memory as DHCP options, so that heap contents such as allocator metadata or pointer values can be interpreted into lease fields. The over-read is bounded to 68 bytes; no memory write, no attacker control over the adjacent bytes and no remote exfiltration primitive has been demonstrated. This issue affects wicked up to and including version 0.6.80.
Severity CVSS v4.0: MEDIUM
Last modification:
27/08/2026

CVE-2026-64896

Publication date:
27/08/2026
Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs.<br /> <br /> This issue affects T2000: before 31.6.
Severity CVSS v4.0: MEDIUM
Last modification:
27/08/2026

CVE-2026-5680

Publication date:
27/08/2026
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-5738

Publication date:
27/08/2026
Improper neutralization of input during web page generation (&amp;#39;cross-site scripting&amp;#39;) vulnerability in BilPark Informatics Technologies Industry and Trade Inc. DoXBASE allows Cross Zone Scripting.<br /> <br /> This issue affects DoXBASE: through 27082026. <br /> NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-59272

Publication date:
27/08/2026
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event.<br /> Spring AMQP 4.1.0<br /> Spring AMQP 4.0.0 - 4.0.4<br /> Spring AMQP 3.2.0 - 3.2.12<br /> Spring AMQP 2.4.18 and earlier
Severity CVSS v4.0: Pending analysis
Last modification:
28/08/2026

CVE-2026-59280

Publication date:
27/08/2026
Applications using Spring Framework&amp;#39;s FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from untrusted input and FreeMarker is configured to resolve templates through SpringTemplateLoader.<br /> Spring Framework 7.0.0 - 7.0.8<br /> Spring Framework 6.2.0 - 6.2.19<br /> Spring Framework 6.1.0 - 6.1.28<br /> Spring Framework 6.0.0 - 6.0.30<br /> Spring Framework 5.3.0 - 5.3.49<br /> Spring Framework 5.2.25.RELEASE and earlier
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026