Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-16257

Publication date:
10/08/2026
The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthenticated users through type juggling when the Arvow AI SEO Writer WordPress plugin before 1.5.4 has not been configured, allowing them to create arbitrary posts and pages and to disclose author account and taxonomy information.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2026

CVE-2026-15229

Publication date:
10/08/2026
The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation.
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2026

CVE-2026-13133

Publication date:
10/08/2026
A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate System32 copy.
Severity CVSS v4.0: HIGH
Last modification:
10/08/2026

CVE-2026-13701

Publication date:
10/08/2026
The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outputting it on the front end of the site, which could allow administrators (including those without the unfiltered_html capability, such as on multisite) to perform Stored Cross-Site Scripting attacks that execute in the context of any visitor viewing affected pages.
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2026

CVE-2026-14206

Publication date:
10/08/2026
The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts.
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2026

CVE-2026-14237

Publication date:
10/08/2026
The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an Outlet Manager to reset any user's password, including an administrator's, and take over the account.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2026

CVE-2026-12971

Publication date:
10/08/2026
The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2026

CVE-2026-13600

Publication date:
10/08/2026
The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator authentication cookie during its scheduled content-synchronization task. On server configurations where the scheduled task executes before the HTTP response is committed, an unauthenticated attacker who triggers the due task can receive the administrator's session cookie and gain administrator access without credentials.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2026

CVE-2026-14211

Publication date:
10/08/2026
The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating sequential identifiers.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2026

CVE-2026-13170

Publication date:
10/08/2026
The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary local PHP files.
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2026

CVE-2026-12570

Publication date:
10/08/2026
A vulnerability in keras-team/keras versions
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2026

CVE-2026-17519

Publication date:
10/08/2026
Rejected reason: This is rejected.
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2026