Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-57894

Publication date:
13/08/2026
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-55402

Publication date:
13/08/2026
CVE-2026-55402 is an out of bounds read vulnerability in Secure Access <br /> servers prior to version 14.57. Attackers with an ‘in the middle’ <br /> position can send specially crafted data to a server causing a <br /> persistent denial of service.
Severity CVSS v4.0: HIGH
Last modification:
13/08/2026

CVE-2026-54481

Publication date:
13/08/2026
Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-55982

Publication date:
13/08/2026
OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-55984

Publication date:
13/08/2026
Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-55986

Publication date:
13/08/2026
Email Management API Bypasses ManageCredentials Feature Restrictions
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-50105

Publication date:
13/08/2026
RSS/Atom feed handlers bypass API-token scope &amp; public-only confinement (incomplete fix of #37698)
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-24791

Publication date:
13/08/2026
Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-42931

Publication date:
13/08/2026
Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-23603

Publication date:
13/08/2026
Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-24059

Publication date:
13/08/2026
The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET request. A holder of a leaked read:user-scoped token can therefore mint a registration token and register a malicious Actions runner that executes workflow jobs with access to repository secrets and source code.
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-13048

Publication date:
13/08/2026
Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename.<br /> <br /> load_lexicon builds the catalog path by appending `Messages/$lang.po` to the directory holding Localizer.pm, where $lang is the language attribute, with no check that it names a bare locale tag. A value holding `../` segments walks out of the message directory, so any readable path with a `.po` suffix is loaded. While parsing the catalog, extract_header_msgstr takes the `Plural-Forms:` header, prefixes `$` to the bare words nplurals, plural and n, and passes the rest verbatim into a string that is evaluated: the nplurals form evaluates the header expression immediately, and the plural_code form compiles it into a subroutine whose body runs when a plural message is localized. A header of `nplurals=2; plural=(system(&amp;#39;...&amp;#39;),0);` therefore runs that command as the catalog loads. The evaluation inherits strict, so an expression that assigns to an undeclared variable fails to compile, while one built from calls alone does not.<br /> <br /> An application that sets the language attribute from request data, an Accept-Language header or a locale parameter, and an attacker who can place a file with a `.po` suffix and chosen contents at a readable path, together give code execution as the application user. The message expansion path is not affected: expand_named substitutes only the placeholder names the caller supplies, and _mangle_value returns the value unchanged.
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026