Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-59842

Publication date:
21/07/2026
A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-59843

Publication date:
21/07/2026
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2026

CVE-2026-59844

Publication date:
21/07/2026
A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2026

CVE-2026-1617

Publication date:
21/07/2026
Improper neutralization of special elements used in an SQL command (&amp;#39;SQL injection&amp;#39;) vulnerability in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama allows SQL Injection.<br /> <br /> This issue affects Turkhotspot 5651 Loglama: from 5.1.2 before 5.1.3.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2026

CVE-2026-16461

Publication date:
21/07/2026
A stack-based buffer overflow was found in rpcbind&amp;#39;s rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), version numbers from a remote RPCBPROC_DUMP reply are written into a fixed-size stack buffer without bounds checking. A user or administrator who runs `rpcinfo -s` against a malicious or compromised rpcbind endpoint could experience a crash or denial of service of the rpcinfo client.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-64606

Publication date:
21/07/2026
Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected<br /> <br /> <br /> This issue affects Apache Fory: from before 1.4.0.<br /> <br /> Users are recommended to upgrade to version 1.4.0, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
27/07/2026

CVE-2026-64609

Publication date:
21/07/2026
Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy deserialization is an opt-in feature; applications that do not use it are not affected.<br /> <br /> This issue affects Apache Fory (formerly Apache Fury): from 0.5.0 before 1.4.0. Versions before 0.11.0 were published under the Maven coordinates org.apache.fury:fury-core.<br /> <br /> Users are recommended to upgrade to version 1.4.0, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
27/07/2026

CVE-2026-62415

Publication date:
21/07/2026
Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-64608

Publication date:
21/07/2026
Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input with an inconsistent schema can cause type confusion and out-of-bounds memory access. Only the C++ implementation is affected; other language implementations of Apache Fory are not.<br /> <br /> This issue affects Apache Fory C++: from 0.14.0 before 1.4.0.<br /> <br /> Users are recommended to upgrade to version 1.4.0, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2026

CVE-2026-1771

Publication date:
21/07/2026
The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all versions up to, and including, 8.14.0 This is due to an incorrect conditional check that prevents file validation from taking place. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site&amp;#39;s server which may make remote code execution possible.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-1372

Publication date:
21/07/2026
The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the `activate_tutor_free()` and `activate_elementor_free()` functions registered as `admin_action_*` handlers. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate the Tutor LMS and Elementor plugins without proper authorization.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-15145

Publication date:
21/07/2026
The Essential Addons for Elementor – Popular Elementor Templates &amp; Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026