Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-42766

Publication date:
09/06/2026
Issue summary: A specially crafted password-encrypted CMS message<br /> can trigger a NULL pointer dereference during CMS decryption.<br /> <br /> Impact summary: This NULL pointer dereference leads to an application crash<br /> and a Denial of Service.<br /> <br /> The CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as<br /> OPTIONAL in the ASN.1 specification and may therefore be absent in specially<br /> crafted inputs. During the password-based CMS decryption the OpenSSL<br /> CMS implementation dereferences this field without first checking whether it<br /> was present.<br /> <br /> An attacker who supplies such a CMS message to an application performing<br /> password-based CMS decryption can trigger an application crash, leading to<br /> a Denial of Service.<br /> <br /> Applications that process password-encrypted CMS messages may be affected.<br /> <br /> The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this<br /> issue, as the affected code is outside the OpenSSL FIPS module boundary.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-40376

Publication date:
09/06/2026
Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-40404

Publication date:
09/06/2026
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-40409

Publication date:
09/06/2026
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-41092

Publication date:
09/06/2026
Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-41098

Publication date:
09/06/2026
Improper neutralization of input during web page generation (&amp;#39;cross-site scripting&amp;#39;) in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-41108

Publication date:
09/06/2026
Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-34183

Publication date:
09/06/2026
Issue summary: Remote peer may exhaust heap memory of the QUIC<br /> server or client by flooding it with packets containing PATH_CHALLENGE<br /> frames.<br /> <br /> Impact summary: A malicious remote peer can cause an unbounded<br /> memory allocation which can lead to an abnormal termination of the<br /> application acting as a QUIC client or server and a Denial of Service.<br /> <br /> A remote peer may exhaust heap memory by flooding the local<br /> QUIC stack with PATH_CHALLENGE frames. The local QUIC stack<br /> allocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives.<br /> The allocated PATH_RESPONSE frame gets freed only when the remote<br /> peer acknowledges reception of the PATH_RESPONSE frame which will<br /> not be done by a malicious peer.<br /> <br /> The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by<br /> this issue. The QUIC stack is outside of OpenSSL FIPS module<br /> boundary.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-34335

Publication date:
09/06/2026
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-34692

Publication date:
09/06/2026
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim&amp;#39;s browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-35188

Publication date:
09/06/2026
Issue summary: A malicious server can exploit TLS OCSP stapling by delivering<br /> a crafted response through the status_request extension, triggering a<br /> double-free in the client&amp;#39;s certificate verification path.<br /> <br /> Impact summary: Successful exploitation allows an attacker to corrupt heap<br /> memory via a double-free, potentially leading to a Denial of Service or<br /> possibly an attacker controlled code execution or other undefined behavior.<br /> <br /> If OCSP stapling is enabled and the TLS client connects to a malicious server,<br /> a crafted OCSP stapled response can trigger a double free in the TLS client<br /> when the stapled response is checked.<br /> <br /> The OCSP stapling is not enabled by default. Reliable code execution<br /> through a double-free is technically complex and highly environment-dependent<br /> but the Denial of Service impact is straightforward to achieve, warranting<br /> Moderate severity.<br /> <br /> No FIPS modules are affected by this issue as the affected code is outside<br /> the OpenSSL FIPS module boundary.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-38615

Publication date:
09/06/2026
DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026