Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-15025

Publication date:
28/07/2026
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator_google_contacts_fetch_labels, automator_mautic_segment_fetch, automator_mautic_tags_fetch, and automator_mautic_render_contact_fields AJAX actions due to a missing capability check and missing nonce verification in the corresponding handlers (ajax_fetch_labels, segments_fetch, tags_fetch, and render_contact_fields). This makes it possible for authenticated attackers, with Subscriber-level access and above, to enumerate sensitive Google Contacts groups/labels and Mautic segments, tags, and contact-field definitions retrieved via integration credentials configured by an administrator, and to consume third-party API quota.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-15411

Publication date:
28/07/2026
The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the spsg_popup_products option with arbitrary attacker-controlled data. The 'ajd_protected' nonce used as the sole gate is exposed to unauthenticated visitors on every frontend page through the BoGo module's wp_localize_script call, rendering it ineffective as an authorization barrier.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-15444

Publication date:
28/07/2026
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the 'coupon_code' parameter in all versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-13110

Publication date:
28/07/2026
The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.1.0. This is due to a missing capability check on the bogo_category_msg_create() AJAX handler, which is registered for both authenticated (wp_ajax_) and unauthenticated (wp_ajax_nopriv_) users and only validates a nonce ('ajd_protected') that is emitted publicly via wp_localize_script() on every frontend page through front_scripts() . This makes it possible for unauthenticated attackers to modify the plugin's BOGO category-message configuration stored in the spsg_bogo_general_settings option by reading the nonce from any public page and POSTing attacker-controlled data to admin-ajax.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-65880

Publication date:
28/07/2026
Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms
Severity CVSS v4.0: CRITICAL
Last modification:
28/07/2026

CVE-2026-63303

Publication date:
28/07/2026
A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolving and serving the requested file. An authenticated attacker with admin privileges can use this vulnerability to read contents of files located in the sibling directory of the webroot via a crafted HTTP request containing ../ sequences in the URI.<br /> <br /> <br /> The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.
Severity CVSS v4.0: MEDIUM
Last modification:
30/07/2026

CVE-2026-63301

Publication date:
28/07/2026
In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language-deletion API endpoint does not enforce an equivalent server-side authorization check. As a result, an authenticated administrator can bypass the UI-level restriction and delete the primary language by sending a direct HTTP request to the API endpoint. Successful deletion of the primary language results in a Denial of Service (DoS) of application.<br /> <br /> <br /> Critically, when combined with a separate Cross-Site Request Forgery (CSRF) vulnerability (CVE-2026-1468) an unauthenticated remote attacker can craft a malicious link, which if visited by an authenticated administrator, will trigger the DoS condition without direct access to the application<br /> <br /> <br /> <br /> <br /> The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.
Severity CVSS v4.0: HIGH
Last modification:
30/07/2026

CVE-2026-63302

Publication date:
28/07/2026
Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated attacker with admin privileges can include arbitrary files located within the application&amp;#39;s directory structure via a crafted HTTP request. Successful exploitation allows disclosure of the server&amp;#39;s directory structure and absolute file paths (path disclosure).<br /> <br /> <br /> <br /> The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.
Severity CVSS v4.0: MEDIUM
Last modification:
30/07/2026

CVE-2026-18028

Publication date:
28/07/2026
The "quick setup" view presented to users after they first create an <br /> event allows to set up the most critical parts of an event in just a few<br /> clicks. This view did not properly check that the user has permission <br /> to change configuration for the given event. An attacker could use a <br /> well-timed request to create products, quotas, set bank transfer <br /> configuration, or connect a stripe account to an event they do not have <br /> access to.
Severity CVSS v4.0: LOW
Last modification:
30/07/2026

CVE-2026-18029

Publication date:
28/07/2026
Our payment integration with GiroCheckout did not properly validate <br /> payment status responses. An attacker could use a successful payment <br /> status response from one payment and supply it to the system for a <br /> different payment, gaining access to multiple valid tickets with only <br /> one payment.
Severity CVSS v4.0: MEDIUM
Last modification:
30/07/2026

CVE-2026-17072

Publication date:
28/07/2026
A flaw was found in GStreamer&amp;#39;s gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC audio stream headers embedded in a Matroska or WebM container file. The vulnerability is triggered by a boundary check that does not account for the full size of the data being copied, allowing a small read past the end of the allocated buffer. An attacker could exploit this by crafting a malicious Matroska or WebM file and tricking a user into opening it, potentially leaking a small amount of adjacent heap memory.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-59248

Publication date:
28/07/2026
Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on the vulnerable server (or client) and cause a denial of service.<br /> <br /> The HPACK and QPACK prefixed-integer decoder cow_hpack_common:dec_big_int/3 in src/cow_hpack_common.hrl (invoked from cow_hpack:decode/2 in src/cow_hpack.erl and from cow_qpack:decode_field_section/3 in src/cow_qpack.erl) reads continuation octets until it sees one whose high bit is clear, evaluating Int + (Value bsl M) at each step with the shift M growing by seven per octet. No limit is enforced on the number of continuation octets, on the resulting bit width, or on the value; the decoder consumes whatever encoded length the peer supplies.<br /> <br /> Because Erlang integers are immutable, each intermediate Value bsl M and each accumulator update allocates a fresh bignum whose digit width grows linearly with the number of octets processed so far. Summed across the whole decode, the transient bignum digit materialization is on the order of the square of the encoded length. A single maximal HPACK indexed representation carried inside one HTTP/2 HEADERS plus one CONTINUATION frame at Cowboy&amp;#39;s default max_frame_size_received can force hundreds of megabytes of transient allocation and garbage-collection churn before the resulting header-table index is rejected as invalid. Repeated or concurrent connections multiply the pressure and can drive the Erlang VM to memory exhaustion.<br /> <br /> Cowlib is the HTTP parser used by Cowboy, RabbitMQ&amp;#39;s management plugin, and other Erlang and Elixir HTTP/2 and HTTP/3 servers and clients, so any exposed endpoint that accepts HPACK or QPACK from an untrusted peer is reachable.<br /> <br /> This issue affects cowlib: from 2.0.0 before 2.19.0.
Severity CVSS v4.0: HIGH
Last modification:
30/07/2026