Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-73572

Publication date:
13/08/2026
In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicious attachment that, when previewed by a user, executes arbitrary JavaScript within the victim's browser session. Successful exploitation may allow an attacker to perform unauthorized actions on behalf of the victim user, potentially leading to data exfiltration or unauthorized access to sensitive information.
Severity CVSS v4.0: Pending analysis
Last modification:
28/08/2026

CVE-2026-73571

Publication date:
13/08/2026
An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send emails without possessing the required delegation or send-as permissions. This occurs in the SaveDraftRequest SOAP handler.
Severity CVSS v4.0: Pending analysis
Last modification:
28/08/2026

CVE-2026-73532

Publication date:
13/08/2026
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.
Severity CVSS v4.0: CRITICAL
Last modification:
14/08/2026

CVE-2026-73559

Publication date:
13/08/2026
vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions CompletionRequest.prompt field in vllm/entrypoints/openai/completion/protocol.py accepts an unbounded list[str] or list[list[int]], prompt_to_seq() in vllm/renderers/inputs/preprocess.py and OnlineRenderer.preprocess_completion() in vllm/renderers/online_renderer.py expand every element, and vllm/entrypoints/openai/completion/serving.py creates one engine generator and response slot per prompt, allowing an authenticated API client to exhaust CPU, memory, async scheduling capacity, engine request slots, and response buffering with one request. This issue is fixed in version 0.26.0.
Severity CVSS v4.0: Pending analysis
Last modification:
14/08/2026

CVE-2026-73514

Publication date:
13/08/2026
The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ability to supply caller-controlled relation names to standardize_address() to trigger memory corruption by providing a rules table with a classification Type value exceeding the fixed class range. Attackers can craft a malicious rules table entry with an oversized rule type value that is used without bounds checking as an index into an internal output-link table, resulting in an out-of-bounds write.
Severity CVSS v4.0: HIGH
Last modification:
13/08/2026

CVE-2026-73515

Publication date:
13/08/2026
PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails to verify that the subsequent string body is contained within the supplied buffer before materializing it into a SQL-visible value, enabling memory disclosure or denial of service.
Severity CVSS v4.0: HIGH
Last modification:
13/08/2026

CVE-2026-73533

Publication date:
13/08/2026
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.
Severity CVSS v4.0: CRITICAL
Last modification:
17/08/2026

CVE-2026-55400

Publication date:
13/08/2026
CVE-2026-55400 is an integer underflow in Secure Access servers prior to<br /> version 14.57. Attackers with an authenticated session can send <br /> specially crafted traffic to a server in a non-default configuration and<br /> cause a persistent denial of service.
Severity CVSS v4.0: MEDIUM
Last modification:
28/08/2026

CVE-2026-55401

Publication date:
13/08/2026
CVE-2026-55401 is a null dereference vulnerability on the load-balancing<br /> sub-system of Secure Access servers prior to 14.57. Attackers can send <br /> an unauthenticated packet to a Secure Access server with load balancing <br /> enabled, which results in the internal load balancer crashing. After a <br /> successful attack, the Secure Access server is still able to accept <br /> connections and is still able to issue a failover to connected clients. ‍ https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
Severity CVSS v4.0: MEDIUM
Last modification:
28/08/2026

CVE-2026-19710

Publication date:
13/08/2026
A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unknown functionality of the file app/admin/departments/view_department.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Severity CVSS v4.0: MEDIUM
Last modification:
14/08/2026

CVE-2026-19744

Publication date:
13/08/2026
Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute arbitrary JavaScript in the application origin via a Markdown link whose URL contains a double quote, which closes the anchor&amp;#39;s href attribute because the renderer&amp;#39;s sanitization step does not escape quotes
Severity CVSS v4.0: MEDIUM
Last modification:
13/08/2026

CVE-2026-19487

Publication date:
13/08/2026
Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.<br /> <br /> The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.<br /> <br /> Example:<br /> <br /> "ABCDE" =~ m/ABCF|BCDE|C/; # matches C at offset 2, not BCDE<br /> "ABCDE" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed<br /> <br /> An alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong.
Severity CVSS v4.0: Pending analysis
Last modification:
28/08/2026