Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-78239

Publication date:
28/08/2026
Xiiaozet LK100W exposes a critical management function that can be <br /> invoked without authentication, allowing a remote attacker to enable <br /> administrative services that should be restricted. Successful <br /> exploitation may permit unauthorized access to the device.
Severity CVSS v4.0: CRITICAL
Last modification:
28/08/2026

CVE-2026-77358

Publication date:
28/08/2026
cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions 0.33.0 through 0.50.0, the TLS-enabled WebSocket client frees the TLS session before closing the WebSocket that still uses it, producing a use-after-free. In WebSocketClient::shutdown_and_close the SSL object is freed and the pointer cleared, but the subsequent WebSocket close still sends a close frame through the SSL socket stream, which holds a raw copy of the now-dangling session pointer and reads from and writes to the freed memory. The same freed-then-used ordering is reachable through the client&amp;#39;s destructor and its connect path, so ordinary teardown of a secure WebSocket connection triggers the defect. This issue is fixed in version 0.50.1.
Severity CVSS v4.0: HIGH
Last modification:
28/08/2026

CVE-2026-76940

Publication date:
28/08/2026
The affected Ebyte device does not restrict repeated authentication <br /> attempts through rate limiting or account lockout mechanisms. This could<br /> allow an attacker to perform automated authentication attacks against <br /> deployments that rely on password based authentication.
Severity CVSS v4.0: HIGH
Last modification:
28/08/2026

CVE-2026-76943

Publication date:
28/08/2026
Xiiaozet LK100Wt contains an authentication weakness within an <br /> administrative service that may allow an attacker to bypass intended <br /> access controls and obtain command execution capabilities. Successful <br /> exploitation could allow unauthorized interaction with privileged <br /> functionality and may lead to complete device compromise.
Severity CVSS v4.0: CRITICAL
Last modification:
28/08/2026

CVE-2026-76945

Publication date:
28/08/2026
The affected Ebyte device relies on client-managed authentication tokens<br /> without sufficient server-side validation. An attacker may replay or <br /> manipulate authentication tokens to gain unauthorized access to <br /> administrative functionality.
Severity CVSS v4.0: HIGH
Last modification:
28/08/2026

CVE-2026-77977

Publication date:
28/08/2026
Ebyte gateway product&amp;#39;s vendor configuration utility does not require authentication before <br /> allowing certain disruptive administrative actions when default <br /> credentials remain configured. An unauthenticated attacker on the <br /> adjacent network could reboot the device or restore factory settings, <br /> resulting in a loss of configuration and service availability.
Severity CVSS v4.0: HIGH
Last modification:
28/08/2026

CVE-2026-77341

Publication date:
28/08/2026
cpp-httplib is a C++ header-only HTTP/HTTPS library. In version 0.49.0, the chunked-response trailer output path writes trailer header names and values directly to the socket without validating them, allowing CRLF sequences in a trailer field to inject additional headers or split the HTTP response. Unlike every other header-writing path in the library, the trailer-writing code applies none of the field-name and field-value checks that reject carriage return and line feed, so an application that places attacker-influenced data into a chunked response trailer emits attacker-controlled CRLF onto the wire. This enables HTTP response splitting, letting an attacker forge response headers or inject a second response. This issue is fixed in version 0.50.0.
Severity CVSS v4.0: MEDIUM
Last modification:
28/08/2026

CVE-2026-75813

Publication date:
28/08/2026
Certain configuration endpoints may lack proper server-side <br /> authorization checks, allowing unauthorized users to access or modify <br /> sensitive device settings. This could result in full compromise of <br /> device functionality.
Severity CVSS v4.0: HIGH
Last modification:
28/08/2026

CVE-2026-75814

Publication date:
28/08/2026
The Ebyte device does not adequately verify the origin or authenticity of <br /> requests submitted to the web management interface. An unauthenticated <br /> remote attacker could persuade an authenticated administrator to visit a<br /> crafted page, causing unauthorized configuration changes or a <br /> disruption of device availability.
Severity CVSS v4.0: HIGH
Last modification:
28/08/2026

CVE-2026-76179

Publication date:
28/08/2026
An improper protection of authentication tokens vulnerability exists in <br /> certain Ebyte gateway products. Authentication tokens used by the web <br /> management interface are insufficiently protected during client-side <br /> session handling, which may allow an attacker with access to exposed <br /> session information to obtain and reuse a valid token. Successful <br /> exploitation could allow an attacker to impersonate an authenticated <br /> user and gain unauthorized access to device management functionality.
Severity CVSS v4.0: CRITICAL
Last modification:
28/08/2026

CVE-2026-76060

Publication date:
28/08/2026
An authenticated OS command injection vulnerability exists in ZoneMinder&amp;#39;s event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP&amp;#39;s exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server.
Severity CVSS v4.0: HIGH
Last modification:
28/08/2026

CVE-2026-75418

Publication date:
28/08/2026
A path traversal vulnerability exists in the built-in preview/development web server of Lektor
Severity CVSS v4.0: Pending analysis
Last modification:
28/08/2026