Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-58425

Publication date:
13/08/2026
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-58427

Publication date:
13/08/2026
Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-58428

Publication date:
13/08/2026
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-58429

Publication date:
13/08/2026
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-57897

Publication date:
13/08/2026
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-58416

Publication date:
13/08/2026
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-55987

Publication date:
13/08/2026
OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-56443

Publication date:
13/08/2026
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-56654

Publication date:
13/08/2026
Privilege Escalation via Access Token Scope Escalation in API
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-56750

Publication date:
13/08/2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-57886

Publication date:
13/08/2026
Cross-repository issue/comment attachment re-linking can expose private attachment content
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-57894

Publication date:
13/08/2026
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026