Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-18275

Publication date:
06/08/2026
Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to run segmentation and transcription against other users' document parts, overwriting their content, via part primary keys supplied to a many=True related field whose queryset restriction was applied to the ManyRelatedField instead of its child_relation and therefore had no effect
Severity CVSS v4.0: Pending analysis
Last modification:
18/08/2026

CVE-2026-18276

Publication date:
06/08/2026
Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the object_cls and object_pk values of a join-room message, which are passed to group_add without an access check
Severity CVSS v4.0: Pending analysis
Last modification:
18/08/2026

CVE-2026-70637

Publication date:
06/08/2026
LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause undefined behavior by issuing LIST followed by ABOR commands without authentication. The control thread closes data_socket and file_fd descriptors while worker threads concurrently operate on the same fields in worker_thread_cleanup, allowing stale file descriptors to be reassigned by the OS and subsequently used by worker threads on unrelated resources, resulting in potential denial of service.
Severity CVSS v4.0: HIGH
Last modification:
06/08/2026

CVE-2026-70646

Publication date:
06/08/2026
aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to force expensive parsing of arbitrary JSON payloads that will ultimately be rejected, leading to unnecessary CPU and memory consumption. Version 3.0.7 fixes the issue. Some workarounds are available. Restrict request body size at the reverse proxy or web framework, rate-limit webhook endpoints, and/or reject oversized requests before JSON parsing.
Severity CVSS v4.0: Pending analysis
Last modification:
08/08/2026

CVE-2026-67261

Publication date:
06/08/2026
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete system takeover by an attacker. This vulnerability is considered critical as it allows an unauthenticated remote attacker to achieve arbitrary code execution as root, potentially compromising the entire VSI deployment and underlying infrastructure. Dell recommends customers to upgrade at the earliest opportunity.
Severity CVSS v4.0: Pending analysis
Last modification:
07/08/2026

CVE-2026-66711

Publication date:
06/08/2026
Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2026

CVE-2026-66710

Publication date:
06/08/2026
Unauthenticated Local File Inclusion in e2pdf
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2026

CVE-2026-66712

Publication date:
06/08/2026
Unauthenticated Broken Access Control in Simple Membership
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2026

CVE-2026-66702

Publication date:
06/08/2026
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2026

CVE-2026-66703

Publication date:
06/08/2026
Contributor Cross Site Scripting (XSS) in MailOptin
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2026

CVE-2026-66706

Publication date:
06/08/2026
Author Cross Site Scripting (XSS) in Subscribe to Comments
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2026

CVE-2026-66707

Publication date:
06/08/2026
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2026