Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-47873

Publication date:
30/07/2026
The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host&amp;#39;s network interfaces (0.0.0.0) rather than restricting them to loopback.<br /> Affected Spring Products and Versions:<br /> Spring Tools for Eclipse: 5.2.0 and earlier
Severity CVSS v4.0: Pending analysis
Last modification:
01/08/2026

CVE-2026-47882

Publication date:
30/07/2026
When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed application. This secret was generated using a non-cryptographic pseudo-random number generator rather than a cryptographically secure source of randomness.<br /> Affected Spring Products and Versions:<br /> Spring Tools for Eclipse: 5.2.0 and earlier
Severity CVSS v4.0: Pending analysis
Last modification:
01/08/2026

CVE-2026-16530

Publication date:
30/07/2026
A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in the `pmLogLoadInDom()` function by sending a specially crafted request. This bypasses a critical bounds check, which can lead to the `pmproxy` service crashing, causing a Denial of Service (DoS). Additionally, this flaw may enable the leakage of sensitive information from the system&amp;#39;s memory.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-16531

Publication date:
30/07/2026
An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-16524

Publication date:
30/07/2026
A command injection flaw in PCP&amp;#39;s linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric.<br /> This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2026

CVE-2026-16526

Publication date:
30/07/2026
A flaw in the PCP linux_sockets module exposes an unsecured internal connection.<br /> An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2026

CVE-2026-16529

Publication date:
30/07/2026
A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2026

CVE-2026-16527

Publication date:
30/07/2026
An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
Severity CVSS v4.0: Pending analysis
Last modification:
07/08/2026

CVE-2026-15255

Publication date:
30/07/2026
The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the identity being requested before returning front-end form submissions, allowing unauthenticated attackers to read other users&amp;#39; form submission data, including personal information.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-15257

Publication date:
30/07/2026
The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing action, allowing unauthenticated attackers to overwrite other users&amp;#39; form submissions and the profile fields of the associated non-administrator WordPress accounts.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-15382

Publication date:
30/07/2026
The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site&amp;#39;s custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site&amp;#39;s custom icon fonts with a single request.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-14923

Publication date:
30/07/2026
The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a REST route that creates and updates posts, because of an operator-precedence flaw in its authorization check. An authenticated user holding only the post-editing capability (such as a Contributor) can create, publish, and overwrite arbitrary Pages, including modifying content authored by higher-privileged users.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026