Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-17570

Publication date:
27/07/2026
Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests.<br /> <br /> This issue affects :<br /> <br /> * Devolutions Server 2026.2.4.0 through 2026.2.12.0<br /> * Devolutions Server 2026.1.23.0 and earlier
Severity CVSS v4.0: Pending analysis
Last modification:
03/08/2026

CVE-2026-17569

Publication date:
27/07/2026
Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint.<br /> <br /> This issue affects :<br /> <br /> * Devolutions Server 2026.2.4.0 through 2026.2.12.0<br /> * Devolutions Server 2026.1.23.0 and earlier
Severity CVSS v4.0: Pending analysis
Last modification:
03/08/2026

CVE-2026-17568

Publication date:
27/07/2026
Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request.<br /> <br /> This issue affects :<br /> <br /> * Devolutions Server 2026.2.4.0 through 2026.2.12.0<br /> * Devolutions Server 2026.1.23.0 and earlier
Severity CVSS v4.0: Pending analysis
Last modification:
03/08/2026

CVE-2026-66729

Publication date:
27/07/2026
facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows unauthenticated remote attackers to crash the server process by sending a crafted Content-Disposition header with an empty field name. Attackers can trigger a uint32_t wraparound in http_mime_parser.h causing an out-of-bounds memory read past the name pointer, resulting in a bus fault that crashes the handling worker with a single POST request.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-66730

Publication date:
27/07/2026
facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unauthenticated remote attacker to permanently freeze worker processes at 100% CPU by sending a multipart/form-data request with a partial closing boundary. The missing progress guard in the parser loop causes http_mime_parse to return 0 bytes consumed without setting done or error flags, causing the calling loop to re-invoke the parser on the same buffer indefinitely, exhausting all workers and permanently disabling the server until manually restarted.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-66731

Publication date:
27/07/2026
facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser that allows unauthenticated remote attackers to crash the server by sending a negative chunk size value. Attackers can send a single POST request with a Transfer-Encoding: chunked header containing a leading minus sign in the chunk size field, causing the parser in http1_parser.h to compute a large positive integer from the negated value, corrupting internal state and moving the read pointer into unmapped memory resulting in a fault.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-66391

Publication date:
27/07/2026
Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket.<br /> <br /> This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0.<br /> <br /> Users are recommended to upgrade to version 10.10.0, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2026

CVE-2026-66390

Publication date:
27/07/2026
Improper Neutralization of Input During Web Page Generation (&amp;#39;Cross-site Scripting&amp;#39;) vulnerability in Apache Wicket.<br /> <br /> This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0.<br /> <br /> Users are recommended to upgrade to version 10.10.0, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2026

CVE-2026-63077

Publication date:
27/07/2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2026

CVE-2026-24252

Publication date:
27/07/2026
NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-17531

Publication date:
27/07/2026
A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the component Unsigned Scheduled Callback. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The attack is considered to have high complexity. The exploitation is known to be difficult. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity CVSS v4.0: LOW
Last modification:
28/07/2026

CVE-2026-17191

Publication date:
27/07/2026
An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections.<br /> <br /> <br /> <br /> <br /> This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
Severity CVSS v4.0: HIGH
Last modification:
30/07/2026