Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-58034

Publication date:
01/07/2026
Improper Neutralization of Input During Web Page Generation (XSS or &amp;#39;Cross-site Scripting&amp;#39;) vulnerability in Wikimedia Foundation CheckUser.<br /> <br /> This vulnerability is associated with program files modules/ext.CheckUser.TempAccounts/components/blockConnectedTempAccountsField.Vue.<br /> <br /> <br /> <br /> This issue affects CheckUser: from 1.46.0-rc.0 before 1.46.0.
Severity CVSS v4.0: NONE
Last modification:
09/07/2026

CVE-2026-58031

Publication date:
01/07/2026
Improper Neutralization of Input During Web Page Generation (XSS or &amp;#39;Cross-site Scripting&amp;#39;) vulnerability in Wikimedia Foundation MediaWiki.<br /> <br /> This vulnerability is associated with program files resources/src/mediawiki.Special.Apisandbox/ApiSandboxLayout.Js.<br /> <br /> <br /> <br /> This issue affects MediaWiki: from 1.46.0-rc.0 before 1.46.0.
Severity CVSS v4.0: NONE
Last modification:
09/07/2026

CVE-2026-23537

Publication date:
01/07/2026
A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticated remote attacker to write arbitrary JSON files to the server&amp;#39;s filesystem. Although the system attempts to restrict file locations, these protections can be bypassed, enabling an attacker to overwrite vital application configurations or startup scripts. Because this flaw requires no credentials or special privileges, any attacker with network access to the server can potentially compromise the integrity of the system. This could lead to unauthorized system modifications, denial of service through disk exhaustion, or potential remote code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
15/07/2026

CVE-2026-2891

Publication date:
01/07/2026
The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities.
Severity CVSS v4.0: HIGH
Last modification:
02/07/2026

CVE-2026-14324

Publication date:
01/07/2026
RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.
Severity CVSS v4.0: Pending analysis
Last modification:
01/07/2026

CVE-2026-14330

Publication date:
01/07/2026
Multiple unbounded alloca() calls in the PulseAudio protocol server.
Severity CVSS v4.0: Pending analysis
Last modification:
01/07/2026

CVE-2026-13602

Publication date:
01/07/2026
We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data:<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> * <br /> <br /> <br /> The payment integration plugins Stripe (included in the core system), pretix-mollie, pretix-oppwa, pretix-bitpay, pretix-payone, pretix-secuconnect, pretix-sofort, and pretix-saferpay<br /> contain a code path that is intended for the transport of session <br /> parameters from a tab with isolated cookies (e.g. in the pretix widget) <br /> to a new tab. For this purpose, a set of session parameters is <br /> cryptographically signed and then passed to the new tab as a URL <br /> parameter. The plugins perform no further validation of the session <br /> parameters, other than the cryptographic signature being valid. This is <br /> fixed with the releases issued today by strictly validating that no <br /> session parameters outside of the scope of the respective plugin may be <br /> set.<br /> <br /> <br /> <br /> <br /> * <br /> <br /> <br /> An unrelated feature in the core system is used to generate redirect links that obfuscate any Referer<br /> headers for outgoing links to prevent leakage of secrets in URLs. This <br /> redirect page also requires cryptographically signed parameters. <br /> Unfortunately, it uses the same key and salt for the signature as the <br /> previously mentioned feature in the payment integration plugins. A <br /> motivated attacker with access to at least one event in the backend can <br /> trick the system into cryptographically signing arbitrary content using <br /> specially crafted links. In combination with the previous issue, the <br /> attacker could use this to set and modify arbitrary parameters on their <br /> user session by injecting the signed parameters into the feature of the <br /> payment providers. This is fixed with the releases issued today by using<br /> different salts for the signature for each plugin and feature.<br /> <br /> <br /> <br /> <br /> * <br /> <br /> <br /> A third, unrelated feature in the core system is used for admin users<br /> to act on behalf of another user, mostly for debugging purposes. With <br /> being able to insert arbitrary parameters into a session, an attacker <br /> can abuse this feature to change their session from their actual user to<br /> any user in the system by guessing a valid user ID. This is fixed with<br /> the release today by requiring unguessable information to be contained <br /> in the session of the user to switch to.
Severity CVSS v4.0: HIGH
Last modification:
02/07/2026

CVE-2026-12374

Publication date:
01/07/2026
Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before v.5.13.1 on macOS allows a local authenticated attacker to escalate privileges to root via a self-signed certificate that bypasses the XPC caller verification and a symlink swap during package installation.
Severity CVSS v4.0: MEDIUM
Last modification:
02/07/2026

CVE-2026-5136

Publication date:
01/07/2026
A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user&amp;#39;s permissions. This allows an authenticated user with usergroup management permissions to attach arbitrary roles, including administrative roles, to a user group and then add themselves as a member. Successful exploitation of this vulnerability leads to full privilege escalation, granting the attacker administrator-level access.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-57692

Publication date:
01/07/2026
Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation.<br /> <br /> This issue affects PrivateContent: from n/a through 9.9.2.
Severity CVSS v4.0: Pending analysis
Last modification:
01/07/2026

CVE-2026-53356

Publication date:
01/07/2026
In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> drm/i915/gem: Fix phys BO pread/pwrite with offset<br /> <br /> sg_page() returns struct page pointer not (void *) so the scaling<br /> of pread/pwrite is wrong for phys BO and wrong parts of BO would be<br /> accessed if non-zero offset is used.<br /> <br /> Last impacted platform with overlay or cursor planes using phys<br /> mapping was Gen3/945G/Lakeport.<br /> <br /> (cherry picked from commit 3e49a2f85070b2fb672c1e0fdba281a4ea3aebe6)
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-53355

Publication date:
01/07/2026
In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net: rds: clear i_sends on setup unwind<br /> <br /> The RDS IB connection teardown path is written so it can run during<br /> partial startup and on repeated shutdown attempts. It uses NULL<br /> pointers to distinguish resources that are still owned from resources<br /> that have already been released.<br /> <br /> When rds_ib_setup_qp() fails after allocating i_sends but before<br /> allocating i_recvs, the sends_out path frees i_sends without clearing<br /> the pointer. A later shutdown pass can still treat that stale pointer<br /> as a live send ring allocation.<br /> <br /> Clear i_sends after vfree() in the error unwind path so the existing<br /> shutdown logic continues to use the correct ownership state.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026