Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-70598

Publication date:
05/08/2026
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rendering frame data received from the GPU process was not fully validated by the main process. A compromised GPU process could cause the main process to read out-of-bounds memory while producing paint event images, disclosing memory or crashing the app. This issue is fixed in 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3.
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2026

CVE-2026-70599

Publication date:
05/08/2026
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, serial-port and media permission checks made from an iframe passed the top-level frame origin to session.setPermissionCheckHandler instead of the requesting iframe origin. Origin-based handler logic could grant a cross-origin iframe device access intended only for the top-level origin. This issue is fixed in 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1.
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2026

CVE-2026-70596

Publication date:
05/08/2026
Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content in feature_image_caption that could be used to hijack another staff user's Ghost Admin session, resulting in privilege escalation. This issue is fixed in 6.54.1.
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2026

CVE-2026-70597

Publication date:
05/08/2026
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the check Electron uses on macOS to confirm it was launched by a same-signed parent process could be bypassed by a local process. Apps that enable fuse-based hardening restricting ELECTRON_RUN_AS_NODE and NODE_OPTIONS to same-signed parents rely on this check, and a local attacker could bypass it and run code inside the signed app, inheriting its TCC permissions and keychain access. This issue is fixed in 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2026

CVE-2026-70595

Publication date:
05/08/2026
Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data being returned. This vulnerability is fixed in 6.54.1.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2026

CVE-2026-60023

Publication date:
05/08/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer.<br /> <br /> This issue affects Apache Answer: through 2.0.1.<br /> <br /> Deleted or pending answers could be retrieved by unauthorized users through the single-answer read path when the parent question remained visible, exposing answer content that should not have been accessible.<br /> Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2026

CVE-2026-60053

Publication date:
05/08/2026
Insufficient Session Expiration vulnerability in Apache Answer.<br /> <br /> This issue affects Apache Answer: through 2.0.1.<br /> <br /> Administrative API keys remained usable after the owning administrator was demoted or the account was marked inactive, suspended, or deleted, allowing continued access until the keys were explicitly removed.<br /> Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
07/08/2026

CVE-2026-53992

Publication date:
05/08/2026
ProjectSend r2029 contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.php that allows remote attackers to inject arbitrary HTML and JavaScript by supplying unsanitized values in the start_date and end_date GET parameters, which are echoed unescaped into HTML attribute values. Attackers can craft a malicious URL that, when followed by an authenticated victim with edit_settings permissions, executes injected scripts in the application origin to steal session cookies or perform unauthorized actions including user management, file management, and application settings changes.
Severity CVSS v4.0: MEDIUM
Last modification:
05/08/2026

CVE-2026-50749

Publication date:
05/08/2026
Improper Authorization vulnerability in Apache Answer.<br /> <br /> This issue affects Apache Answer: through 2.0.1.<br /> <br /> Any authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject operation.<br /> Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2026

CVE-2026-48912

Publication date:
05/08/2026
Improper Input Validation vulnerability in Apache Answer.<br /> <br /> This issue affects Apache Answer: through 2.0.1.<br /> <br /> A missing ownership check in the avatar-cleanup logic allows any authenticated user to delete other users&amp;#39; uploaded files by supplying their file URLs.<br /> Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2026

CVE-2026-48911

Publication date:
05/08/2026
Insufficient Verification of Data Authenticity vulnerability in Apache Answer.<br /> <br /> This issue affects Apache Answer: through 2.0.1.<br /> <br /> A missing authorization check in the external-login email binding flow allows unauthenticated attackers to take over arbitrary user accounts by tricking victims into clicking a crafted confirmation link.<br /> Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2026

CVE-2026-49331

Publication date:
05/08/2026
A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy forwards client-supplied identity headers (X-Forwarded-User, X-Forwarded-Email, X-Forwarded-Access-Token) to the upstream application without stripping them. An unauthenticated attacker can inject forged identity headers on whitelisted paths.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2026