Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-16641

Publication date:
25/08/2026
Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-16642

Publication date:
25/08/2026
Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-15088

Publication date:
25/08/2026
Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*.
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-80182

Publication date:
25/08/2026
In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and outlive, the credential used to obtain them. The delegation restrictions that block these operations did not consistently apply to all delegated token types, allowing an OAuth1-scoped token, for example, to create application credentials or authorize OAuth1 request tokens despite those operations being restricted for other delegated token types. All Keystone deployments that permit delegated authentication through OAuth1 access tokens, application credentials, or trusts are affected.
Severity CVSS v4.0: HIGH
Last modification:
26/08/2026

CVE-2026-80184

Publication date:
25/08/2026
In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) could be submitted to the token-method authentication path for reauthentication to escape their intended project scope. When an application credential token was presented with no explicit scope, Keystone would issue a new token scoped to the credential owner's default project rather than the project for which the credential was issued, bypassing the intended project boundary. All Keystone deployments that permit delegated authentication through OAuth1 access tokens, application credentials, or trusts are affected.
Severity CVSS v4.0: HIGH
Last modification:
26/08/2026

CVE-2026-80185

Publication date:
25/08/2026
BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-80186

Publication date:
25/08/2026
A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-79804

Publication date:
25/08/2026
A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e5ea59432e39ceaa0fa5. Affected by this issue is some unknown functionality of the file /search.php. Performing a manipulation of the argument search_box results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.
Severity CVSS v4.0: MEDIUM
Last modification:
26/08/2026

CVE-2026-79845

Publication date:
25/08/2026
A vulnerability was identified in code-projects Simple Inventory System 1.0. This vulnerability affects unknown code of the file /InventoryManagement/edit.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
Severity CVSS v4.0: MEDIUM
Last modification:
26/08/2026

CVE-2026-78619

Publication date:
25/08/2026
Punk::Plugin::TOTP versions before 0.05 for Perl accept another account&amp;#39;s recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically.<br /> <br /> The helper searches the recovery model for the submitted code&amp;#39;s digest alone, across every user&amp;#39;s rows, so the ownership test that follows is the only thing binding a code to the account it was issued to. That test compares the row&amp;#39;s user_id with the challenged user&amp;#39;s id through Perl&amp;#39;s integer coercion, and an identifier with no leading digits coerces to zero, so any two of them compare equal. User models keyed on a username, an email address or a UUID hit that case, and a numeric key compares as intended.<br /> <br /> The challenge route feeds a submitted value to the helper once TOTP verification fails, so an attacker who knows a victim&amp;#39;s password and holds a recovery code of their own passes the victim&amp;#39;s second factor.
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-78655

Publication date:
25/08/2026
Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session.<br /> <br /> The POST handler on challenge_path keeps the failure count as tries inside the totp_pending record in the session, raising it on each rejected code and deleting the pending record once it reaches attempts, five by default. Punk::Session carries the session in a signed cookie unless the application declares a store, and keeps no server-side record, so an earlier value of the same session stays valid until the expiry stamped inside it. A client that saves the cookie before its failed attempts and presents it again gets the pending record back with its counter, and the limit never fires. The replayed record is accepted while its own expiry, pending_ttl seconds from the challenge and 300 by default, has not passed.<br /> <br /> Sessions declared with a store are not affected: the pending record and its counter then live server-side.<br /> <br /> The attempt limit does not bound guessing of the second factor, which is left to the per-address rate limit the plugin registers on the same path, 30 requests per 60 seconds.
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2026

CVE-2026-73180

Publication date:
25/08/2026
Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended.<br /> <br /> <br /> <br /> This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.<br /> <br /> <br /> <br /> The following versions were EOL at the time the CVE was created but are <br /> known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected.<br /> <br /> <br /> <br /> Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026