Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-53502

Publication date:
31/07/2026
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boundary validation, allowing traversal outside FILE_LOADER_ROOT_PATH through watermark or frame filter input. This issue is fixed in 7.8.0.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-53503

Publication date:
31/07/2026
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(, , ) filter passes the user-controlled value to a C extension (thumbor/ext/filters/_convolution.c) where it is used as a divisor (for % and /) without validating columns > 0. When columns=0, the C code triggers undefined behavior; on x86_64 this reliably results in a fatal divide-by-zero trap (SIGFPE) and crashes the Thumbor process, causing a remote denial of service. This issue is fixed in 7.8.0.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-18481

Publication date:
31/07/2026
Stored cross-site scripting in the participant URL handling in AWS Ops <br /> Wheel before PR #168 might allow an authenticated remote user to steal <br /> session tokens and escalate to full administrative control of the <br /> deployed instance via a crafted participant_url value containing a <br /> dangerous URI scheme.<br /> <br /> <br /> <br /> <br /> <br /> <br /> To remediate this issue, users should redeploy from the latest version of aws-ops-wheel.
Severity CVSS v4.0: MEDIUM
Last modification:
04/08/2026

CVE-2026-18321

Publication date:
31/07/2026
Buffer overflow in NTPsec&amp;#39;s Zyfer refclock allows local attacker to crash ntpd
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-25552

Publication date:
31/07/2026
Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a misconfigured Nginx configuration. Attackers can append attacker-controlled values to the header chain using the $proxy_add_x_forwarded_for directive to present an arbitrary IP address, circumventing Ghost&amp;#39;s rate-limiting mechanisms on self-hosted instances.
Severity CVSS v4.0: MEDIUM
Last modification:
31/07/2026

CVE-2026-54729

Publication date:
31/07/2026
DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost as safe when DNS resolver 1.1.1.1 returns NXDOMAIN because dns.resolve4 yields no address and no dns.lookup fallback occurs, allowing server-side request forgery. This issue is fixed in version 1.0.5.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-54725

Publication date:
31/07/2026
vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and MutateSecret call newVaultClient in pkg/webhook/webhook.go, and vault.security.banzaicloud.io/vault-serviceaccount can cause a ServiceAccount JWT to be sent to an attacker-controlled Vault address. This issue is fixed in version 1.23.1.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-54737

Publication date:
31/07/2026
@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursively merges user-supplied objects without filtering proto, constructor, and prototype, allowing properties to be written to Object.prototype. This issue is fixed in version 2.0.5.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-55100

Publication date:
31/07/2026
hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query strings instead of using encodeURIComponent() and URLSearchParams, allowing path traversal and query parameter injection. This issue is fixed in version 0.5.2.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-34490

Publication date:
31/07/2026
Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data.<br /> <br /> This issue affects XAAP Application: before 1.53.
Severity CVSS v4.0: MEDIUM
Last modification:
10/08/2026

CVE-2026-34495

Publication date:
31/07/2026
Improper neutralization of input during web page generation (&amp;#39;cross-site scripting&amp;#39;) vulnerability in Johnson Controls FM Systems Employee allows Stored XSS.<br /> <br /> This issue affects FM Systems Employee: before 2025.3.1.
Severity CVSS v4.0: MEDIUM
Last modification:
10/08/2026

CVE-2026-34497

Publication date:
31/07/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS).<br /> <br /> This issue affects FM Systems Employee: before 2025.3.1.
Severity CVSS v4.0: MEDIUM
Last modification:
10/08/2026