Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-61455

Publication date:
10/07/2026
Grav before 2.0.1 contains a decompression bomb vulnerability in ZipArchiver::extract() that lacks limits on uncompressed size, file count, and nesting depth. Attackers can supply a crafted ZIP archive that expands to fill available disk space, causing denial of service by exhausting storage resources.
Severity CVSS v4.0: HIGH
Last modification:
10/07/2026

CVE-2026-61437

Publication date:
10/07/2026
PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFlow._resolve_pydantic_class (src/praisonai-agents/praisonaiagents/workflows/workflows.py). When a workflow step uses a string output_pydantic reference, the framework locates and imports a sibling tools.py from the workflow file's directory via importlib exec_module without sandboxing, ignoring the PRAISONAI_ALLOW_*_TOOLS environment variables. An attacker who controls a workflow file and its sibling tools.py can execute arbitrary Python code with the workflow runner's privileges when the workflow is executed via WorkflowManager or after load_yaml.
Severity CVSS v4.0: HIGH
Last modification:
14/07/2026

CVE-2026-60089

Publication date:
10/07/2026
PraisonAI (pip package praisonaiagents) before 1.6.78 automatically loads defaults from a project-local .praisonai/config.toml when constructing an Agent, and does not validate the defaults.output.output_file path. A repository-controlled config file can set output_file to an absolute or '..' traversal path; when the developer subsequently calls agent.start() without explicitly passing an output parameter, PraisonAI writes the agent response to that path (creating parent directories as needed), allowing an untrusted checked-out project to overwrite files outside the project root with the privileges of the user running PraisonAI.
Severity CVSS v4.0: MEDIUM
Last modification:
10/07/2026

CVE-2026-60091

Publication date:
10/07/2026
PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api/v1/runs endpoint. The webhook_url parameter is validated at request time but re-resolved at connection time, allowing attackers to use DNS rebinding to reach internal services with a blind SSRF attack.
Severity CVSS v4.0: MEDIUM
Last modification:
10/07/2026

CVE-2026-61431

Publication date:
10/07/2026
PraisonAI before 4.6.78 contains a path traversal vulnerability in ContextGatherer that fails to validate include paths in .praisoncontext and .praisoninclude files. Attackers can supply absolute paths or parent directory traversal sequences to read arbitrary files outside the workspace and include their contents in the generated context bundle.
Severity CVSS v4.0: MEDIUM
Last modification:
10/07/2026

CVE-2026-60086

Publication date:
10/07/2026
PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks threats classified as CRITICAL, requiring three or more detector families to match simultaneously. Attackers can craft single or double-vector prompt injections that are classified as HIGH threat level and pass through unblocked to reach the model.
Severity CVSS v4.0: MEDIUM
Last modification:
14/07/2026

CVE-2026-59794

Publication date:
10/07/2026
In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data
Severity CVSS v4.0: Pending analysis
Last modification:
10/07/2026

CVE-2026-59791

Publication date:
10/07/2026
In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
Severity CVSS v4.0: Pending analysis
Last modification:
10/07/2026

CVE-2026-59795

Publication date:
10/07/2026
In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
Severity CVSS v4.0: Pending analysis
Last modification:
13/07/2026

CVE-2026-59792

Publication date:
10/07/2026
In JetBrains IntelliJ IDEA before 2026.1.4, <br /> 2026.2 code execution via path traversal in project workspace ID handling was possible
Severity CVSS v4.0: Pending analysis
Last modification:
14/07/2026

CVE-2026-59793

Publication date:
10/07/2026
In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration
Severity CVSS v4.0: Pending analysis
Last modification:
14/07/2026

CVE-2026-59796

Publication date:
10/07/2026
In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
Severity CVSS v4.0: Pending analysis
Last modification:
14/07/2026