Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-48855

Publication date:
10/06/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery.<br /> <br /> The SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client without calling chroot_filename/2 to strip the backend root prefix. An authenticated SFTP client can create a symlink inside the chroot pointing to /; ssh_sftpd resolves the target to the absolute backend root and stores it on disk. Reading the symlink back via SSH_FXP_READLINK returns that absolute path, for example /data/sftp, instead of the chrooted value /.<br /> <br /> The information disclosed is the absolute filesystem path of the SFTP root directory and of any symlink targets within it. No file contents, credentials, or access to paths outside the root directory are obtainable through this issue alone.<br /> <br /> This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl.<br /> <br /> This issue affects OTP from OTP 17.0 before OTP 29.0.2, OTP 28.5.0.2 and OTP 27.3.4.13, corresponding to ssh from 3.0.1 before 6.0.1, 5.5.2.1 and 5.2.11.8.
Severity CVSS v4.0: LOW
Last modification:
24/07/2026

CVE-2026-46497

Publication date:
10/06/2026
Crawlee is a web scraping and browser automation library. From version 1.0.0 to before version 1.7.0, Crawlee is vulnerable to SSRF via sitemap-derived URLs. This issue has been patched in version 1.7.0.
Severity CVSS v4.0: LOW
Last modification:
10/06/2026

CVE-2026-45569

Publication date:
10/06/2026
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validation to block .. in config_file_name and configver for improved security") added a line in app/modules/config/config.py:462. This is tuple-membership, not substring containment — &amp;#39;..&amp;#39; in (a, b, c) evaluates to True only if any of a, b, c is equal to the literal string &amp;#39;..&amp;#39;. For any realistic path-traversal payload (../../etc/passwd, ..\\..\\etc\\passwd, etc.) the check returns False and the patch silently lets the payload through. At time of publication, there are no publicly available patches.
Severity CVSS v4.0: Pending analysis
Last modification:
11/06/2026

CVE-2026-45565

Publication date:
10/06/2026
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, EscapedString (app/modules/roxywi/class_models.py:16-30) is the centralised Pydantic validator used on dozens of fields including SSH credential name, username, description, etc. Its if/elif/elif/else flow returns the metacharacter-stripped value without also enforcing the .. block. An attacker who appends a single ;, &amp;, |, $, or backtick to a .. payload routes the value through the strip arm, where .. survives unblocked and the result is not shlex.quote()&amp;#39;d either. At time of publication, there are no publicly available patches.
Severity CVSS v4.0: Pending analysis
Last modification:
10/06/2026

CVE-2026-45566

Publication date:
10/06/2026
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the login flow allow-lists next URLs by rejecting strings containing https:// or http:// substrings, then constructs https://{request.host}{next_url} and the JS client redirects via window.location.replace(). The block does not consider the userinfo@host syntax. next=@evil.example/path produces https://victim.example@evil.example/path, which all modern browsers route to evil.example. At time of publication, there are no publicly available patches.
Severity CVSS v4.0: Pending analysis
Last modification:
10/06/2026

CVE-2026-45567

Publication date:
10/06/2026
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypass vulnerability via &amp;#39;api&amp;#39; substring in URL + unauthenticated /api/gpt. At time of publication, there are no publicly available patches.
Severity CVSS v4.0: Pending analysis
Last modification:
10/06/2026

CVE-2026-25700

Publication date:
10/06/2026
Improper Restriction of Security Token Assignment vulnerability in Apache Answer.<br /> <br /> This issue affects Apache Answer: through 2.0.0.<br /> <br /> Previously issued administrative tokens were not invalidated after an administrator account was suspended, deleted, or deactivated, allowing continued access to administrative APIs until the token expired.<br /> Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
19/06/2026

CVE-2026-9045

Publication date:
10/06/2026
During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.
Severity CVSS v4.0: HIGH
Last modification:
10/06/2026

CVE-2026-6090

Publication date:
10/06/2026
A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.
Severity CVSS v4.0: HIGH
Last modification:
10/06/2026

CVE-2026-7516

Publication date:
10/06/2026
A vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets in the Chinese market, that could allow a website visited by the built-in browser to overwrite system clipboard contents.
Severity CVSS v4.0: MEDIUM
Last modification:
10/06/2026

CVE-2026-8637

Publication date:
10/06/2026
A potential uncontrolled search path vulnerability was reported in the LanSchool Classic client application that could allow a local authenticated user to execute arbitrary code with elevated privileges.
Severity CVSS v4.0: HIGH
Last modification:
10/06/2026

CVE-2026-8335

Publication date:
10/06/2026
A missing authentication check on the Aix‑DB "/llm/process_llm_out" endpoint allows unauthenticated clients to execute arbitrary "SELECT" SQL queries and retrieve database data, as the endpoint lacks the token validation enforced on all other application endpoints.<br /> All releases up to 1.2.4 are considered vulnerable. Status of next releases is unknown as the vulnerability has not been addressed by any patch.
Severity CVSS v4.0: HIGH
Last modification:
10/06/2026