Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-18614

Publication date:
03/08/2026
A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Severity CVSS v4.0: HIGH
Last modification:
12/08/2026

CVE-2026-18616

Publication date:
03/08/2026
A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the component wg-server.so Native Plugin. The manipulation of the argument public_key leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Severity CVSS v4.0: HIGH
Last modification:
12/08/2026

CVE-2026-18615

Publication date:
03/08/2026
A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-bin/glc of the component wg-server.so Native Plugin. Executing a manipulation of the argument private_key can lead to command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Severity CVSS v4.0: HIGH
Last modification:
12/08/2026

CVE-2025-15631

Publication date:
03/08/2026
A<br /> cryptographic weakness exists in affected Omada devices where site credentials<br /> are protected using a legacy hashing algorithm that does not provide sufficient<br /> protection.<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> An attacker<br /> who obtains access to stored credential data may be able to recover valid credentials<br /> to gain unauthorized access to affected devices or management environments.
Severity CVSS v4.0: MEDIUM
Last modification:
07/08/2026

CVE-2025-15630

Publication date:
03/08/2026
A race<br /> condition exists in the cloud-based Omada device adoption process when an<br /> attacker may be able to interact with the adoption workflow before a legitimate<br /> device completes registration, resulting in provisioning information being<br /> delivered to an attacker.<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> Successful<br /> exploitation may allow disclosure of provisioning information intended for a<br /> legitimate device.
Severity CVSS v4.0: MEDIUM
Last modification:
07/08/2026

CVE-2025-15629

Publication date:
03/08/2026
A cryptographic<br /> weakness exists in the Omada adoption protocol where session encryption keys<br /> used to protect communications between controllers and managed devices may be<br /> predictable due to insufficient entropy in session key generation.<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> An attacker<br /> who successfully intercepts adoption-related communications may be able to recover<br /> session encryption keys and decrypt affected communications.
Severity CVSS v4.0: MEDIUM
Last modification:
07/08/2026

CVE-2025-15628

Publication date:
03/08/2026
Affected<br /> Omada devices rely on embedded certificates that are shared across deployments<br /> to establish trust between controllers and managed devices.<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> An attacker<br /> who obtains the embedded certificates may be able to impersonate trusted<br /> controllers or devices and intercept affected communications.
Severity CVSS v4.0: HIGH
Last modification:
07/08/2026

CVE-2025-15627

Publication date:
03/08/2026
A cryptographic<br /> weakness exists in the Omada adoption protocol. <br /> The protocol relies on hard-coded cryptographic keys to establish trust and<br /> protect authentication exchanges between controllers and managed devices during<br /> device adoption.<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> An attacker may<br /> be able to impersonate trusted controllers or managed devices and gain access<br /> to sensitive adoption-related communications.
Severity CVSS v4.0: MEDIUM
Last modification:
07/08/2026

CVE-2025-15544

Publication date:
03/08/2026
A cryptographic<br /> weakness exists in the Omada device adoption process.  During adoption, authentication credentials associated<br /> with site management are transmitted using a weak hashing algorithm that does<br /> not provide sufficient protection. <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> An attacker who<br /> successfully intercepts adoption-related authentication traffic may be able to<br /> recover valid credentials and gain unauthorized access to managed devices or<br /> controller-managed environments.
Severity CVSS v4.0: MEDIUM
Last modification:
07/08/2026

CVE-2026-61523

Publication date:
03/08/2026
WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arbitrary PHP code by submitting malicious content through the droplet Code field, which is written verbatim to a publicly accessible PHP file with no content sanitization. Attackers can save a PHP webshell via the save_droplet handler to a predictable path inside the modules directory, enabling unauthenticated users to achieve remote code execution by making direct HTTP requests to the written file.
Severity CVSS v4.0: HIGH
Last modification:
03/08/2026

CVE-2026-61524

Publication date:
03/08/2026
WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that allows authenticated administrators to achieve remote code execution by uploading a crafted ZIP archive containing a PHP webshell alongside a valid info.php metadata file. Attackers can place the malicious archive through the module installation interface, causing the application to extract the webshell into a web-accessible modules/ subdirectory where it becomes immediately executable by any unauthenticated user via direct HTTP request.
Severity CVSS v4.0: HIGH
Last modification:
03/08/2026

CVE-2026-40717

Publication date:
03/08/2026
Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access (&amp;#39;Link Following&amp;#39;) vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
07/08/2026