Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-33267

Publication date:
29/07/2026
Improper Input Validation vulnerability in Apache Traffic Server.<br /> <br /> This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3.<br /> <br /> Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
Severity CVSS v4.0: HIGH
Last modification:
05/08/2026

CVE-2026-63236

Publication date:
29/07/2026
An improper access control vulnerability in<br /> Koollab LMS allowed an<br /> unauthenticated attacker to read another user&amp;#39;s name, internal identifier,<br /> scores, lesson status, lesson position, and cached lesson state via the SCORM<br /> API endpoint.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-63237

Publication date:
29/07/2026
A TOTP two-factor authentication bypass vulnerability in<br /> Koollab LMS allowed an<br /> attacker to supply a client-controlled seed to generate a matching one-time<br /> password and bypass the second authentication factor, potentially enabling<br /> unauthorised access to administrator accounts.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-63238

Publication date:
29/07/2026
An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated<br /> attacker to take over any account, including administrator accounts, by<br /> supplying a valid user UUID without providing primary credentials via the 2FA<br /> validation endpoint.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-63239

Publication date:
29/07/2026
A hard-coded AWS IAM credentials vulnerability<br /> in Koollab LMS allowed<br /> an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing<br /> sensitive data and enabling malicious content injection, job manipulation, or<br /> email interception.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-63240

Publication date:
29/07/2026
An information disclosure vulnerability in Koollab LMS allowed an authenticated learner<br /> to obtain correct quiz answers from the course status endpoint without<br /> completing the assessment legitimately, compromising the integrity of<br /> assessments.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-63241

Publication date:
29/07/2026
An insecure direct object reference<br /> vulnerability in Koollab LMS allowed an authenticated user to query the course completion progress<br /> of any other user without authorisation, disclosing private learning progress<br /> information.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-63242

Publication date:
29/07/2026
A business logic vulnerability in Koollab LMS<br /> allowed an<br /> authenticated learner to set their lesson completion status to completed via<br /> the SCORM commit endpoint without viewing the lesson material, compromising<br /> training and completion records.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-63228

Publication date:
29/07/2026
An unrestricted image upload vulnerability in<br /> Koollab LMS allowed<br /> an authenticated attacker to upload malicious content disguised as an image<br /> file via the feedback mail registration endpoint, potentially enabling further<br /> attacks on the server.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-63229

Publication date:
29/07/2026
A pre-authentication blind SQL injection<br /> vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via<br /> the SSO OAuth endpoint to read sensitive database contents, including<br /> personally identifiable information, credentials, and valid JWT tokens that may<br /> enable account takeover.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-63230

Publication date:
29/07/2026
A pre-authentication error-based SQL injection<br /> vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database<br /> contents, including personally identifiable information, credentials, and valid<br /> JWT tokens that may enable account takeover, via the SCORM report endpoint.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-63231

Publication date:
29/07/2026
A post-authentication SQL injection<br /> vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via<br /> the face-to-face runs update endpoint to read the entire application database<br /> and obtain valid JWT tokens for account takeover.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026