Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-18381

Publication date:
30/07/2026
A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL, allowing the attacker to obtain the token.
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2026

CVE-2026-18382

Publication date:
30/07/2026
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token endpoint. When authentication.type is set to service-account, the operator sends the tenant's Red Hat SSO client_id and client_secret to this user-controlled URL, allowing the attacker to obtain the credentials.
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2026

CVE-2026-15397

Publication date:
30/07/2026
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration AJAX handler. This makes it possible for authenticated attackers, with shop manager-level access and above, to install and activate arbitrary WordPress.org plugins.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-22620

Publication date:
30/07/2026
Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-22621

Publication date:
30/07/2026
Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-22622

Publication date:
30/07/2026
Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-18363

Publication date:
30/07/2026
A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the password reset process, the application retrieves the timestamp associated with the provided token and checks whether the configured validity period has expired. Consequently, the expiry check is only performed if the timestamp lookup fails, allowing tokens with an existing timestamp to bypass the intended expiry validation. Therefore, an attacker able to obtain a valid password reset token could reuse it to perform an unauthorised password reset and compromise the affected account.
Severity CVSS v4.0: CRITICAL
Last modification:
30/07/2026

CVE-2026-18369

Publication date:
30/07/2026
A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated ACME account holder can exploit this to perform server-side request forgery (SSRF), making the Dogtag server send HTTP GET requests to internal network services. With the InMemory database backend, the response body of internal targets is disclosed to the attacker through the ACME challenge error.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-16970

Publication date:
30/07/2026
The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2026

CVE-2026-16971

Publication date:
30/07/2026
The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-18360

Publication date:
30/07/2026
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-18361

Publication date:
30/07/2026
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026