Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-75337

Publication date:
28/08/2026
The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The user-controlled path is concatenated to the preview root directory without any normalization, allowing anonymous attackers to read files outside the preview root.
Severity CVSS v4.0: Pending analysis
Last modification:
28/08/2026

CVE-2026-75339

Publication date:
28/08/2026
The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any logged-in user can upload arbitrary files, and any anonymous attacker can download them.
Severity CVSS v4.0: Pending analysis
Last modification:
28/08/2026

CVE-2026-75417

Publication date:
28/08/2026
A SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in the get_arrchildid() function within application/admin/controller/category.class.php, where the user-controlled parentid parameter is concatenated directly into a FIND_IN_SET() SQL clause without proper sanitization. This allows an authenticated administrator to execute arbitrary SQL queries via boolean-based blind injection, potentially leading to full database compromise.
Severity CVSS v4.0: Pending analysis
Last modification:
28/08/2026

CVE-2026-73125

Publication date:
28/08/2026
Ebyte device web management interface does not consistently enforce <br /> authentication before granting access to administrative functionality. <br /> An unauthenticated remote attacker could access sensitive configuration <br /> information, modify device settings, or disrupt availability.
Severity CVSS v4.0: CRITICAL
Last modification:
28/08/2026

CVE-2026-73809

Publication date:
28/08/2026
A cleartext transmission of sensitive information vulnerability exists <br /> in certain Ebyte gateway products. The web management interface does not<br /> adequately protect sensitive communications using transport-layer <br /> encryption. An attacker with access to network traffic could intercept <br /> authentication or session-related information transmitted between a user<br /> and the affected device. Successful exploitation could result in <br /> disclosure of sensitive information and unauthorized access to device <br /> management functionality.
Severity CVSS v4.0: HIGH
Last modification:
28/08/2026

CVE-2026-73839

Publication date:
28/08/2026
Administrative credentials may be exposed in plaintext within the Ebyte <br /> device&amp;#39;s management interface, increasing the risk of credential <br /> compromise through visual or remote observation. This undermines the <br /> confidentiality of device access.
Severity CVSS v4.0: MEDIUM
Last modification:
28/08/2026

CVE-2026-71396

Publication date:
28/08/2026
Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable automatic traction control.
Severity CVSS v4.0: MEDIUM
Last modification:
28/08/2026

CVE-2026-71187

Publication date:
28/08/2026
The Ebyte device relies on client side authentication logic that can be <br /> reproduced by unauthenticated users. An attacker may generate valid <br /> authentication requests and bypass authentication to obtain <br /> administrative access to the device.
Severity CVSS v4.0: CRITICAL
Last modification:
28/08/2026

CVE-2026-67560

Publication date:
28/08/2026
Bendix EC80 Brake ECU<br /> is vulnerable to a stack-based buffer overflow, which may allow an <br /> attacker to crash the ECU. A crafted payload can then be used to <br /> remotely execute arbitrary code or inject arbitrary CAN bus traffic. <br /> This could cause the loss of the ABS function, steering assist, <br /> speedometer, and shifting.
Severity CVSS v4.0: HIGH
Last modification:
28/08/2026

CVE-2026-68967

Publication date:
28/08/2026
Bendix EC80 Brake ECU is vulnerable to an out-of-bounds write, which could allow an attacker <br /> to deliver a payload that could establish an arbitrary write primitive, <br /> which could crash the ECU.
Severity CVSS v4.0: HIGH
Last modification:
28/08/2026

CVE-2026-69658

Publication date:
28/08/2026
MQTT credentials and control traffic are transmitted in cleartext, <br /> exposing sensitive information to network-level attackers. This may <br /> enable unauthorized device impersonation and disruption of messaging <br /> functions.
Severity CVSS v4.0: CRITICAL
Last modification:
28/08/2026

CVE-2026-68929

Publication date:
28/08/2026
FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, the WeChat (iLink) share-channel endpoints authorize requests using only the public shareId, with no authenticated identity or team-ownership check. As a result, an unauthenticated attacker who knows a victim team&amp;#39;s shareId can take that team&amp;#39;s WeChat bot offline or hijack the channel to their own bot: the logout endpoint is gated only by an existence check yet wipes the outLink&amp;#39;s stored WeChat token, and the QR-code status endpoint performs no authorization at all and writes attacker-supplied bot credentials into the outLink identified by shareId. By generating a QR for a victim shareId, scanning it with their own WeChat, and calling the status endpoint, an attacker binds the victim team&amp;#39;s app to the attacker&amp;#39;s bot, exposing the app&amp;#39;s private responses, displacing the legitimate binding, and consuming the victim&amp;#39;s resources. The shareId is exposed in every shared chat URL, iframe, and embed, so it is not a secret. This issue is fixed in version 4.15.2.
Severity CVSS v4.0: CRITICAL
Last modification:
28/08/2026