Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-31843

Publication date:
16/04/2026
The goodoneuz/pay-uz Laravel package (
Severity CVSS v4.0: CRITICAL
Last modification:
17/04/2026

CVE-2025-15621

Publication date:
16/04/2026
Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication
Severity CVSS v4.0: MEDIUM
Last modification:
17/04/2026

CVE-2026-3369

Publication date:
16/04/2026
The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded image title in versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity CVSS v4.0: Pending analysis
Last modification:
22/04/2026

CVE-2026-3489

Publication date:
16/04/2026
The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to SQL Injection via the 'packages' parameter in versions up to, and including, 3.6.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Severity CVSS v4.0: Pending analysis
Last modification:
22/04/2026

CVE-2026-3155

Publication date:
16/04/2026
The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete OneSignal metadata for arbitrary posts.
Severity CVSS v4.0: Pending analysis
Last modification:
22/04/2026

CVE-2025-12624

Publication date:
16/04/2026
Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This failure to enforce revocation allows previously issued, valid tokens to remain usable, enabling continued access to protected resources by locked user accounts.<br /> <br /> The security consequence is that a locked user account can maintain access to protected resources through the use of existing, unexpired access tokens. This creates a security gap where access control policies are bypassed, potentially leading to unauthorized data access or actions until the tokens naturally expire.
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2026

CVE-2025-6024

Publication date:
16/04/2026
The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script injection.<br /> An attacker can leverage this by injecting malicious scripts into the authentication endpoint. This can result in the user&amp;#39;s browser being redirected to a malicious website, manipulation of the web page&amp;#39;s user interface, or the retrieval of information from the browser. However, session hijacking is not possible due to the httpOnly flag protecting session-related cookies.
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2026

CVE-2024-8010

Publication date:
16/04/2026
The component accepts XML input through the publisher without disabling external entity resolution. This allows malicious actors to submit a crafted XML payload that exploits the unescaped external entity references.<br /> <br /> By leveraging this vulnerability, a malicious actor can read confidential files from the product&amp;#39;s file system or access limited HTTP resources reachable via HTTP GET requests to the vulnerable product.
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2026

CVE-2024-4867

Publication date:
16/04/2026
The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or proper output encoding. This deficiency allows a malicious actor to inject script content that is executed within the context of a user&amp;#39;s browser.<br /> <br /> By leveraging this cross-site scripting vulnerability, a malicious actor can cause the browser to redirect to a malicious website, make changes to the UI of the web page, or retrieve information from the browser. However, session hijacking is not possible as all session-related sensitive cookies are protected by the httpOnly flag.
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2026

CVE-2024-10242

Publication date:
16/04/2026
The authentication endpoint fails to adequately validate user-supplied input before reflecting it back in the response. This allows an attacker to inject malicious script payloads into the input parameters, which are then executed by the victim&amp;#39;s browser.<br /> <br /> Successful exploitation can enable an attacker to redirect the user&amp;#39;s browser to a malicious website, modify the UI of the web page, or retrieve information from the browser. However, the impact is limited as session-related sensitive cookies are protected by the httpOnly flag, preventing session hijacking.
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2026

CVE-2026-23772

Publication date:
16/04/2026
Dell Storage Manager - Replay Manager for Microsoft Servers, version(s) 8.0, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
17/04/2026

CVE-2024-2374

Publication date:
16/04/2026
The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entities. This omission allows malicious actors to craft XML payloads that exploit the parser&amp;#39;s behavior, leading to the inclusion of external resources.<br /> <br /> By leveraging this vulnerability, an attacker can read confidential files from the file system and access limited HTTP resources reachable by the product. Additionally, the vulnerability can be exploited to perform denial of service attacks by exhausting server resources through recursive entity expansion or fetching large external resources.
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2026