Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-63550

Publication date:
30/07/2026
The MMS BER decoder contains a boundary-handling flaw in the processing <br /> of certain fields within confirmed-request messages. When a crafted <br /> BER-encoded element is received over an established MMS session (TCP <br /> port 102), the decoder may advance its internal read position <br /> incorrectly, leading to a heap out-of-bounds read. This condition causes<br /> the MMS handling process to terminate unexpectedly, resulting in a <br /> denial-of-service.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-65421

Publication date:
30/07/2026
The MMS BER decoder contains a flaw in decoding fixed-width BER fields <br /> (boolean/integer): an attacker-supplied length value is not validated, <br /> causing a read past the end of a heap buffer. This leads to termination <br /> of the MMS service process and a denial-of-service condition.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-65423

Publication date:
30/07/2026
An integer overflow in the UA_Variant arrayDimensions product <br /> computation in open62541 may allow a remote attacker to trigger an <br /> out-of-bounds write.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-66349

Publication date:
30/07/2026
The MMS server connection handler contains a flaw in its processing of <br /> BER-encoded request data. When an MMS confirmed request PDU containing <br /> an extended BER tag is received over an established session, the decoder<br /> may advance its internal buffer incorrectly due to a missing bounds <br /> check. This results in a one byte heap out-of-bounds read and causes the<br /> MMS service process to terminate, leading to a denial-of-service <br /> condition.
Severity CVSS v4.0: MEDIUM
Last modification:
31/07/2026

CVE-2026-56758

Publication date:
30/07/2026
The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS<br /> connection establishment. When parsing certain fields within the <br /> calling AP title, an attacker controlled length value of zero or one may<br /> cause the parser to read past the end of a heap buffer.
Severity CVSS v4.0: MEDIUM
Last modification:
31/07/2026

CVE-2026-61893

Publication date:
30/07/2026
A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an <br /> inflated object count causes TestCommand_getFromBuffer to read one byte <br /> past the end of the heap-allocated message buffer.
Severity CVSS v4.0: MEDIUM
Last modification:
31/07/2026

CVE-2026-10031

Publication date:
30/07/2026
SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in directories where download, upload, or overwrite permissions are denied. Attackers can exploit the create_symlinks permission combined with read and write access in one directory to read or modify files in restricted directories, as operations are authorized against the link&amp;#39;s directory permissions rather than the dereferenced target&amp;#39;s directory permissions.
Severity CVSS v4.0: LOW
Last modification:
31/07/2026

CVE-2026-63033

Publication date:
30/07/2026
A crafted IEC 60870-5-104 I-frame with a declared object count exceeding<br /> what fits in the ASDU body causes InformationObject_ParseObjectAddress <br /> to read one byte past the end of the heap-allocated message buffer.
Severity CVSS v4.0: MEDIUM
Last modification:
31/07/2026

CVE-2026-68562

Publication date:
30/07/2026
A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node&amp;#39;s Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own local files and copy them to the managed node. This vulnerability leads to information disclosure, potentially exposing sensitive controller-side data such as private keys or credentials.
Severity CVSS v4.0: Pending analysis
Last modification:
03/08/2026

CVE-2026-68563

Publication date:
30/07/2026
A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data` option is selected, a PostgreSQL data backup archive is created with insecure permissions. This allows a local non-root user on the managed node to read sensitive archived PostgreSQL data, leading to information disclosure.
Severity CVSS v4.0: Pending analysis
Last modification:
03/08/2026

CVE-2026-62246

Publication date:
30/07/2026
Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and GetDefaultDatastoreUsername(), allowing distinct tenants with colliding normalized identifiers to share control-plane state and read, modify, or destroy another tenant&amp;#39;s Kubernetes data. This issue is fixed in version 26.7.4-edge.
Severity CVSS v4.0: Pending analysis
Last modification:
01/08/2026

CVE-2026-64816

Publication date:
30/07/2026
RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_processing.rs. On Windows, a UNC path in lutPath causes an outbound SMB connection to an attacker-controlled host, leaking the victim&amp;#39;s NTLMv2 credentials. The vulnerable code path is reachable through two vectors: community presets fetched automatically from the remote preset repository when the victim opens the Community tab, and individual preset files imported directly by the victim via the preset import feature (handle_import_presets_from_file in file_management.rs). The second vector does not require control of the community preset repository and is triggered when a user imports a preset file shared through Discord, forums, or similar channels.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026