Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-14180

Publication date:
11/08/2026
A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the remaining chunk size and state flags. By sending a specially crafted request with an extremely large chunk size, an attacker can cause these values to overlap, tricking the parser into thinking a request has finished prematurely. This can allow a second, "smuggled" request to be processed out of sync, potentially bypassing security controls.
Severity CVSS v4.0: Pending analysis
Last modification:
14/08/2026

CVE-2026-11738

Publication date:
11/08/2026
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
Severity CVSS v4.0: MEDIUM
Last modification:
12/08/2026

CVE-2026-11739

Publication date:
11/08/2026
A command injection vulnerability in certain affected NETGEAR Nighthawk <br /> devices allows a network-adjacent attacker with the ability to intercept<br /> and modify local network traffic (attacker in the middle) to compromise<br /> the confidentiality and integrity of the affected device.
Severity CVSS v4.0: MEDIUM
Last modification:
12/08/2026

CVE-2026-11814

Publication date:
11/08/2026
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
Severity CVSS v4.0: MEDIUM
Last modification:
12/08/2026

CVE-2026-11734

Publication date:
11/08/2026
A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.
Severity CVSS v4.0: LOW
Last modification:
12/08/2026

CVE-2026-11735

Publication date:
11/08/2026
A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router&amp;#39;s software and functionality.
Severity CVSS v4.0: LOW
Last modification:
12/08/2026

CVE-2026-11736

Publication date:
11/08/2026
A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.
Severity CVSS v4.0: LOW
Last modification:
12/08/2026

CVE-2026-11737

Publication date:
11/08/2026
Insufficient input validation vulnerability in the listed <br /> NETGEAR models allows authenticated administrators connected to the <br /> local network to make unauthorized modification to the device software and <br /> functionality.
Severity CVSS v4.0: MEDIUM
Last modification:
12/08/2026

CVE-2026-11733

Publication date:
11/08/2026
A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device.
Severity CVSS v4.0: LOW
Last modification:
12/08/2026

CVE-2025-31114

Publication date:
11/08/2026
Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use of eval when processing metadata JSON. An attacker with access to the Fooocus web UI may be able to execute arbitrary code on the instance. As of time of publication, no known patched versions are available, but a suggested fix pull request is available.
Severity CVSS v4.0: CRITICAL
Last modification:
13/08/2026

CVE-2026-72920

Publication date:
11/08/2026
SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser, CreateAccessKey, PutPolicy, and related IAM RPCs to mint credentials and gain S3 administrative control. This issue is fixed in versions 4.24.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2026

CVE-2026-73066

Publication date:
11/08/2026
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract&amp;#39;s deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolve.cpp to wrap the convolution output-channel count, undersizing the forward-pass output buffer while writes use the unwrapped element count and causing a heap out-of-bounds write during OCR recognition. This issue is fixed in version 5.5.3.
Severity CVSS v4.0: MEDIUM
Last modification:
11/08/2026