Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-76940

Publication date:
28/08/2026
The affected Ebyte device does not restrict repeated authentication <br /> attempts through rate limiting or account lockout mechanisms. This could<br /> allow an attacker to perform automated authentication attacks against <br /> deployments that rely on password based authentication.
Severity CVSS v4.0: HIGH
Last modification:
28/08/2026

CVE-2026-76943

Publication date:
28/08/2026
Xiiaozet LK100Wt contains an authentication weakness within an <br /> administrative service that may allow an attacker to bypass intended <br /> access controls and obtain command execution capabilities. Successful <br /> exploitation could allow unauthorized interaction with privileged <br /> functionality and may lead to complete device compromise.
Severity CVSS v4.0: CRITICAL
Last modification:
28/08/2026

CVE-2026-76945

Publication date:
28/08/2026
The affected Ebyte device relies on client-managed authentication tokens<br /> without sufficient server-side validation. An attacker may replay or <br /> manipulate authentication tokens to gain unauthorized access to <br /> administrative functionality.
Severity CVSS v4.0: HIGH
Last modification:
28/08/2026

CVE-2026-77977

Publication date:
28/08/2026
Ebyte gateway product&amp;#39;s vendor configuration utility does not require authentication before <br /> allowing certain disruptive administrative actions when default <br /> credentials remain configured. An unauthenticated attacker on the <br /> adjacent network could reboot the device or restore factory settings, <br /> resulting in a loss of configuration and service availability.
Severity CVSS v4.0: HIGH
Last modification:
28/08/2026

CVE-2026-76060

Publication date:
28/08/2026
An authenticated OS command injection vulnerability exists in ZoneMinder&amp;#39;s event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP&amp;#39;s exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server.
Severity CVSS v4.0: HIGH
Last modification:
28/08/2026

CVE-2026-75813

Publication date:
28/08/2026
Certain configuration endpoints may lack proper server-side <br /> authorization checks, allowing unauthorized users to access or modify <br /> sensitive device settings. This could result in full compromise of <br /> device functionality.
Severity CVSS v4.0: HIGH
Last modification:
28/08/2026

CVE-2026-75814

Publication date:
28/08/2026
The Ebyte device does not adequately verify the origin or authenticity of <br /> requests submitted to the web management interface. An unauthenticated <br /> remote attacker could persuade an authenticated administrator to visit a<br /> crafted page, causing unauthorized configuration changes or a <br /> disruption of device availability.
Severity CVSS v4.0: HIGH
Last modification:
28/08/2026

CVE-2026-76179

Publication date:
28/08/2026
An improper protection of authentication tokens vulnerability exists in <br /> certain Ebyte gateway products. Authentication tokens used by the web <br /> management interface are insufficiently protected during client-side <br /> session handling, which may allow an attacker with access to exposed <br /> session information to obtain and reuse a valid token. Successful <br /> exploitation could allow an attacker to impersonate an authenticated <br /> user and gain unauthorized access to device management functionality.
Severity CVSS v4.0: CRITICAL
Last modification:
28/08/2026

CVE-2026-75418

Publication date:
28/08/2026
A path traversal vulnerability exists in the built-in preview/development web server of Lektor
Severity CVSS v4.0: Pending analysis
Last modification:
28/08/2026

CVE-2026-75419

Publication date:
28/08/2026
go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() function in app/admin/service/internal/data/data.go and app/app/service/internal/data/data.go returns a no-op authorization engine (noop.State{}), so the authz middleware always allows requests. Any authenticated user (regardless of role or tenant) can invoke administrative APIs such as deleting users, resetting passwords, and creating tenants.
Severity CVSS v4.0: Pending analysis
Last modification:
28/08/2026

CVE-2026-75337

Publication date:
28/08/2026
The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The user-controlled path is concatenated to the preview root directory without any normalization, allowing anonymous attackers to read files outside the preview root.
Severity CVSS v4.0: Pending analysis
Last modification:
28/08/2026

CVE-2026-75339

Publication date:
28/08/2026
The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any logged-in user can upload arbitrary files, and any anonymous attacker can download them.
Severity CVSS v4.0: Pending analysis
Last modification:
28/08/2026