Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-46316

Publication date:
09/06/2026
In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry<br /> <br /> vgic_its_invalidate_cache() walks the per-ITS translation cache with<br /> xa_for_each() and drops the cache&amp;#39;s reference on each entry with<br /> vgic_put_irq(). It puts the iterated pointer, though, rather than the<br /> value returned by xa_erase().<br /> <br /> The function is called from contexts that do not exclude one another: the<br /> ITS command handlers hold its_lock, the GITS_CTLR write path holds<br /> cmd_lock, and the path that clears EnableLPIs in a redistributor&amp;#39;s<br /> GICR_CTLR holds neither. Two or more of them can drain the same cache<br /> concurrently, and if each one observes the same entry, erases it and then<br /> puts it, the single reference the cache holds on that entry is dropped<br /> more than once. The entry can then be freed while an ITE still maps it.<br /> <br /> xa_erase() is atomic and returns the previous entry, so put only the entry<br /> that this context actually removed. The cache reference is then dropped<br /> exactly once per entry even when the invalidations run concurrently, and<br /> the behavior is unchanged when only one context runs.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2017-20251

Publication date:
09/06/2026
WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by injecting malicious shortcodes through the WordPress REST API. Attackers can send POST requests to the wp-json/wp/v2/posts endpoint with crafted content containing insert_php shortcodes to include and execute remote PHP files on the server.
Severity CVSS v4.0: CRITICAL
Last modification:
21/07/2026

CVE-2026-11764

Publication date:
09/06/2026
When creating an export of all reusable media, the secrets of connected <br /> gift cards were included in the export even if the user creating the <br /> export does not have permission to view gift cards. This is inconsistent<br /> with the UI and API where only the first letters of the gift card <br /> secret are shown. Therefore, it allows circumventing a permission <br /> boundary.
Severity CVSS v4.0: LOW
Last modification:
23/07/2026

CVE-2026-2638

Publication date:
09/06/2026
A vulnerability in the quarantine and restore workflow of the X-VPN macOS website versions 77.0 through 77.5 allow a local attacker to leverage a race condition and symlink manipulation to achieve privileged file corruption.
Severity CVSS v4.0: HIGH
Last modification:
23/07/2026

CVE-2017-20244

Publication date:
09/06/2026
Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to read arbitrary database information by exploiting an unescaped POST parameter. Attackers can inject SQL code through the &amp;#39;mwpformid&amp;#39; parameter in requests to the admin-ajax.php endpoint with the &amp;#39;send_mwp_form&amp;#39; action to extract sensitive database contents.
Severity CVSS v4.0: HIGH
Last modification:
21/07/2026

CVE-2017-20245

Publication date:
09/06/2026
Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by exploiting the unescaped &amp;#39;idsignup&amp;#39; POST parameter. Attackers can send crafted requests to the admin-ajax.php endpoint with malicious SQL payloads in the &amp;#39;idsignup&amp;#39; parameter to read arbitrary data from the database.
Severity CVSS v4.0: HIGH
Last modification:
21/07/2026

CVE-2017-20246

Publication date:
09/06/2026
KittyCatfish 2.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to read database contents by exploiting an unescaped GET parameter. Attackers can inject SQL code through the &amp;#39;kc_ad&amp;#39; parameter in base.css.php or kittycatfish.php to extract sensitive database information using boolean-based blind or time-based blind techniques.
Severity CVSS v4.0: HIGH
Last modification:
21/07/2026

CVE-2017-20247

Publication date:
09/06/2026
WordPress Plugin PICA Photo Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the aid parameter. Attackers can send GET requests with crafted SQL payloads in the aid parameter to extract sensitive database information including user credentials and table contents.
Severity CVSS v4.0: HIGH
Last modification:
21/07/2026

CVE-2017-20248

Publication date:
09/06/2026
Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the imgname parameter. Attackers can send requests to asgallDownload.php with directory traversal sequences ../ to access sensitive files outside the intended directory.
Severity CVSS v4.0: HIGH
Last modification:
21/07/2026

CVE-2017-20249

Publication date:
09/06/2026
Apptha Slider Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the albid parameter. Attackers can send GET requests with crafted SQL payloads in the albid parameter to extract sensitive database information including user credentials and authentication hashes.
Severity CVSS v4.0: HIGH
Last modification:
21/07/2026

CVE-2017-20250

Publication date:
09/06/2026
Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the albid parameter. Attackers can send requests to macdownload.php with directory traversal sequences to access sensitive files like wp-load.php outside the intended plugin directory.
Severity CVSS v4.0: HIGH
Last modification:
21/07/2026

CVE-2016-20063

Publication date:
09/06/2026
Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries by injecting malicious code through the message parameter. Attackers can access the admin interface and supply crafted SQL statements in the message parameter to extract sensitive database information including user credentials and site configuration data.
Severity CVSS v4.0: HIGH
Last modification:
21/07/2026