Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-34490

Publication date:
31/07/2026
Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data.<br /> <br /> This issue affects XAAP Application: before 1.53.
Severity CVSS v4.0: MEDIUM
Last modification:
10/08/2026

CVE-2026-21662

Publication date:
31/07/2026
Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files.<br /> <br /> This issue affects FM Systems Employee: before 2025.3.1.
Severity CVSS v4.0: MEDIUM
Last modification:
10/08/2026

CVE-2026-67822

Publication date:
31/07/2026
Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled &amp;#39;GO&amp;#39; and &amp;#39;index&amp;#39; parameters into a 64-byte stack buffer without length restriction, leading to stack overflow.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-58047

Publication date:
31/07/2026
HTTP Smuggling in cPanel allows potential leak of credentials.
Severity CVSS v4.0: MEDIUM
Last modification:
07/08/2026

CVE-2026-58048

Publication date:
31/07/2026
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
Severity CVSS v4.0: CRITICAL
Last modification:
07/08/2026

CVE-2026-54707

Publication date:
31/07/2026
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files setting in cli/onionshare_cli/web/receive_mode.py, where ReceiveModeRequest._get_file_stream() writes multipart file[] data to disk despite the text-only setting. This issue is fixed in version 2.6.4.
Severity CVSS v4.0: Pending analysis
Last modification:
01/08/2026

CVE-2026-52856

Publication date:
31/07/2026
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-54706

Publication date:
31/07/2026
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/send_base_mode.py through SendBaseModeWeb.set_file_info() and stream_individual_file(), allowing remote recipients of Share or Website mode to read local files outside the selected directory. This issue is fixed in version 2.6.4.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-52855

Publication date:
31/07/2026
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token_id}}, and {{config.docker.registries}} from the full daemon configuration. This issue is fixed in version 1.12.3.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-67607

Publication date:
31/07/2026
LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thread_cleanup() function of ftpserv.c that allows remote unauthenticated attackers to destabilize or crash the daemon by triggering unsynchronized access to shared per-connection state without holding the required mutex lock. Attackers can send a data-transfer command such as LIST followed immediately by ABOR to exploit the missing synchronization on shared context and detached thread id reuse, resulting in daemon destabilization or crash which can lead to a denial of service. The 2.3.1 patch only narrowed the timing window (an extra re-check and reordered cleanup), it never added the missing lock, so the underlying race remains.
Severity CVSS v4.0: HIGH
Last modification:
03/08/2026

CVE-2026-59231

Publication date:
31/07/2026
Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server to arbitrary attacker-chosen destinations via unvalidated URLs stored in the finding images field or the report client_logo field, which the server-side headless browser fetches while rendering the report.
Severity CVSS v4.0: MEDIUM
Last modification:
31/07/2026

CVE-2026-59232

Publication date:
31/07/2026
Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the create or update lead permission to execute arbitrary JavaScript in the application origin via HTML markup stored in the lead name field, which the view renders through Blade&amp;#39;s unescaped output directive and inside a JavaScript string literal in an onclick attribute.
Severity CVSS v4.0: MEDIUM
Last modification:
31/07/2026