Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-66421

Publication date:
30/07/2026
OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message containing inline event handler payloads such as an img tag with an onerror attribute within the 60-character rendering budget, which is stored in the session transcript and interpolated unsanitized into innerHTML on the default landing page, allowing theft of session tokens and unauthorized calls to authenticated administrative endpoints including agent instruction file modification.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-66720

Publication date:
30/07/2026
The GOOSE subscriber component improperly validates the UTC timestamp <br /> field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 <br /> multicast messages. A specially crafted GOOSE frame containing an <br /> undersized timestamp field can trigger a heap out-of-bounds read during <br /> message processing, causing the process to crash and resulting in a <br /> denial-of-service condition.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-66369

Publication date:
30/07/2026
The GOOSE parser contains an off-by-one boundary-handling flaw that can <br /> be triggered by a single unauthenticated Layer-2 multicast frame on the <br /> process bus. When specific GOOSE message fields are processed, the <br /> parser advances its internal buffer position incorrectly, resulting in a<br /> heap out-of-bounds read. On affected platforms, this condition reliably<br /> terminates the subscriber process and causes a denial-of-service.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-63035

Publication date:
30/07/2026
A heap use-after-free vulnerability in the TransferSubscriptions service<br /> in open62541 may allow an authenticated attacker to cause a denial of <br /> service or potentially execute arbitrary code.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-63362

Publication date:
30/07/2026
An unsigned integer underflow in the PubSub signature verification path <br /> in open62541 may allow a remote attacker to cause a denial of service <br /> via a crafted UDP packet.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-63550

Publication date:
30/07/2026
The MMS BER decoder contains a boundary-handling flaw in the processing <br /> of certain fields within confirmed-request messages. When a crafted <br /> BER-encoded element is received over an established MMS session (TCP <br /> port 102), the decoder may advance its internal read position <br /> incorrectly, leading to a heap out-of-bounds read. This condition causes<br /> the MMS handling process to terminate unexpectedly, resulting in a <br /> denial-of-service.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-65421

Publication date:
30/07/2026
The MMS BER decoder contains a flaw in decoding fixed-width BER fields <br /> (boolean/integer): an attacker-supplied length value is not validated, <br /> causing a read past the end of a heap buffer. This leads to termination <br /> of the MMS service process and a denial-of-service condition.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-65423

Publication date:
30/07/2026
An integer overflow in the UA_Variant arrayDimensions product <br /> computation in open62541 may allow a remote attacker to trigger an <br /> out-of-bounds write.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-66349

Publication date:
30/07/2026
The MMS server connection handler contains a flaw in its processing of <br /> BER-encoded request data. When an MMS confirmed request PDU containing <br /> an extended BER tag is received over an established session, the decoder<br /> may advance its internal buffer incorrectly due to a missing bounds <br /> check. This results in a one byte heap out-of-bounds read and causes the<br /> MMS service process to terminate, leading to a denial-of-service <br /> condition.
Severity CVSS v4.0: MEDIUM
Last modification:
31/07/2026

CVE-2026-56758

Publication date:
30/07/2026
The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS<br /> connection establishment. When parsing certain fields within the <br /> calling AP title, an attacker controlled length value of zero or one may<br /> cause the parser to read past the end of a heap buffer.
Severity CVSS v4.0: MEDIUM
Last modification:
31/07/2026

CVE-2026-61893

Publication date:
30/07/2026
A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an <br /> inflated object count causes TestCommand_getFromBuffer to read one byte <br /> past the end of the heap-allocated message buffer.
Severity CVSS v4.0: MEDIUM
Last modification:
31/07/2026

CVE-2026-10031

Publication date:
30/07/2026
SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in directories where download, upload, or overwrite permissions are denied. Attackers can exploit the create_symlinks permission combined with read and write access in one directory to read or modify files in restricted directories, as operations are authorized against the link&amp;#39;s directory permissions rather than the dereferenced target&amp;#39;s directory permissions.
Severity CVSS v4.0: LOW
Last modification:
31/07/2026