Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-63248

Publication date:
04/08/2026
In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagnostics for other active sessions, exposing usernames, login history, authentication mechanisms, security modes and policies, and public client certificates.
Severity CVSS v4.0: MEDIUM
Last modification:
05/08/2026

CVE-2026-18809

Publication date:
04/08/2026
Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153.0.3.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2026

CVE-2026-18806

Publication date:
04/08/2026
External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality.<br /> <br /> This issue affects pardus-image-writer: before 0.9.0.
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2026

CVE-2026-10709

Publication date:
04/08/2026
A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2026

CVE-2026-10710

Publication date:
04/08/2026
A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2026

CVE-2026-66883

Publication date:
04/08/2026
Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize module) renders the user agent session binding inert, removing a defense in depth control against replay of a stolen session.<br /> <br /> This vulnerability is associated with program files lib/oidcc/plug/authorize.ex and lib/oidcc/plug/authorization_callback.ex, and program routines Oidcc.Plug.Authorize.call/2 and Oidcc.Plug.AuthorizationCallback.call/2.<br /> <br /> Oidcc.Plug.Authorize.call/2 reads the initiating client&amp;#39;s user agent with get_req_header(conn, "User-Agent"). Plug lowercases incoming header names, but get_req_header/2 matches the supplied key exactly and performs no normalization of its own, so the mixed-case lookup always returns an empty list and nil is written into the session. On the callback side, Oidcc.Plug.AuthorizationCallback treats a stored nil user agent as nothing to compare and returns :ok without inspecting the request. The two behaviours combine so that the check passes unconditionally on every request, including for deployments that explicitly opted in with check_useragent: true, and an authorization callback can be completed from a different user agent than the one that initiated the flow without detection. The check fails open silently, with no error and no log entry, so a deployment cannot tell the binding is absent.<br /> <br /> The impact is limited to defense in depth. The inert check does not by itself allow an attacker to complete an authorization flow; it removes one layer that would otherwise hinder use of a stolen or leaked session, such as an exfiltrated session cookie replayed from a different client. The CSRF/state, nonce, and PKCE checks are unaffected and continue to function. Deployments that never enabled check_useragent are not affected in practice, since they never expected the binding. The corresponding lookup in Oidcc.Plug.AuthorizationCallback correctly uses the lowercase key and is not affected.<br /> <br /> This issue affects oidcc_plug: from 0.1.0-alpha.3 before 0.5.0.
Severity CVSS v4.0: MEDIUM
Last modification:
04/08/2026

CVE-2026-66884

Publication date:
04/08/2026
Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback module) allows an attacker to make a victim&amp;#39;s browser complete an authorization flow the victim never initiated.<br /> <br /> This vulnerability is associated with program file lib/oidcc/plug/authorization_callback.ex and program routine Oidcc.Plug.AuthorizationCallback.call/2.<br /> <br /> A callback request that carries no Oidcc.Plug.Authorize session is processed with every security check disabled rather than being rejected. call/2 substitutes permissive defaults for the absent session, and each downstream check treats its value as nothing to compare and returns :ok, so the nonce, state, PKCE, peer IP and user agent checks are all skipped. A separate clause of check_state/2 also accepts a state-less request when a verifier is present.<br /> <br /> An attacker obtains an authorization code for their own provider account, then induces the victim to visit the callback endpoint with that code and no state parameter. The application signs the victim in as the attacker, so the victim&amp;#39;s subsequent actions occur in the attacker&amp;#39;s account where the attacker can read them. Applications reusing one callback for both signing in and linking a provider account are further exposed to account takeover, the attacker&amp;#39;s account becoming linked to the victim&amp;#39;s.<br /> <br /> The permissive fallback serves no conforming flow. Third-party-initiated login reaches a relying party at a separate login initiation endpoint and causes it to send a fresh authentication request, and this library implements no such endpoint. Oidcc.Plug.Authorize always sends a state parameter, which an authorization server must echo, so no legitimate callback lacks one.<br /> <br /> This issue affects oidcc_plug: from 0.2.0-beta.1 before 0.5.0.
Severity CVSS v4.0: LOW
Last modification:
04/08/2026

CVE-2026-10050

Publication date:
04/08/2026
In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes.<br /> <br /> <br /> <br /> This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons.<br /> <br /> <br /> <br /> If the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: `αβ123` converts to `??123`.<br /> <br /> <br /> <br /> An attacker can send a request with a digest `Authorization` header crafted with a password made of only `?` characters; the server would match any password of the same length that contains non-ISO-8859-1 characters.<br /> <br /> <br /> <br /> Recent HTTP Digest [RFC-7616](https://datatracker.ietf.org/doc/html/rfc7616) supports a `charset` parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords.
Severity CVSS v4.0: HIGH
Last modification:
08/08/2026

CVE-2026-14202

Publication date:
04/08/2026
Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting.<br /> <br /> This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2026

CVE-2026-14465

Publication date:
04/08/2026
Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Replay).<br /> <br /> This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2026

CVE-2026-14804

Publication date:
04/08/2026
Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable.<br /> <br /> This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2026

CVE-2026-14838

Publication date:
04/08/2026
Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Session Hijacking.<br /> <br /> This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2026