Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-78614

Publication date:
28/08/2026
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.
Severity CVSS v4.0: HIGH
Last modification:
28/08/2026

CVE-2026-78615

Publication date:
28/08/2026
A Reflected Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's report detail page allows an attacker to execute arbitrary JavaScript in a authenticated user's browser with a specially crafted URL.
Severity CVSS v4.0: MEDIUM
Last modification:
28/08/2026

CVE-2026-78616

Publication date:
28/08/2026
A Stored Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's Trusted CA certificate configuration allows an authenticated administrator to execute arbitrary JavaScript in another authenticated administrator's web browser by saving a carefully crafted certificate.
Severity CVSS v4.0: MEDIUM
Last modification:
28/08/2026

CVE-2026-78617

Publication date:
28/08/2026
WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account lockout setting is enabled, brute-force attempts are blocked after a defined number of failed attempts, but this setting is not enabled by default.
Severity CVSS v4.0: MEDIUM
Last modification:
28/08/2026

CVE-2026-78618

Publication date:
28/08/2026
A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operations within a single logical flow by sending a specially crafted request.
Severity CVSS v4.0: MEDIUM
Last modification:
28/08/2026

CVE-2026-78195

Publication date:
28/08/2026
A Cross-Site Scripting (XSS) vulnerability in the WatchGuard Dimension Backup Historical Data feature allows an authenticated administrator user to execute arbitrary JavaScript in another user's browser.
Severity CVSS v4.0: MEDIUM
Last modification:
28/08/2026

CVE-2026-78495

Publication date:
28/08/2026
A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Remote Backup Connection Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
Severity CVSS v4.0: MEDIUM
Last modification:
28/08/2026

CVE-2026-78498

Publication date:
28/08/2026
A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Email Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
Severity CVSS v4.0: MEDIUM
Last modification:
28/08/2026

CVE-2026-78499

Publication date:
28/08/2026
A server-side request forgery (SSRF) vulnerability WatchGuard Dimension FTP Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
Severity CVSS v4.0: MEDIUM
Last modification:
28/08/2026

CVE-2026-78500

Publication date:
28/08/2026
A blind server-side request forgery (SSRF) vulnerability WatchGuard Dimension Database Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
Severity CVSS v4.0: MEDIUM
Last modification:
28/08/2026

CVE-2026-78610

Publication date:
28/08/2026
WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to visit a crafted link or page can change that administrator's passphrase to an attacker-chosen value without the administrator's consent.
Severity CVSS v4.0: HIGH
Last modification:
28/08/2026

CVE-2026-78612

Publication date:
28/08/2026
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.
Severity CVSS v4.0: HIGH
Last modification:
28/08/2026