Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-25659

Publication date:
05/06/2026
Ericsson<br /> Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling<br /> of Missing Values (CWE-230) vulnerability where an attacker continuously<br /> sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.
Severity CVSS v4.0: HIGH
Last modification:
08/06/2026

CVE-2026-50256

Publication date:
05/06/2026
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library&amp;#39;s maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2&amp;#39;s alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to copy that name into the undersized stack buffer without further checks. This may be used to crash the server, or for privilege escalation if the X server runs as root.
Severity CVSS v4.0: Pending analysis
Last modification:
15/07/2026

CVE-2026-50257

Publication date:
05/06/2026
A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privilege escalation if the X server runs as root.
Severity CVSS v4.0: Pending analysis
Last modification:
15/07/2026

CVE-2026-25657

Publication date:
05/06/2026
Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.
Severity CVSS v4.0: HIGH
Last modification:
08/06/2026

CVE-2026-25658

Publication date:
05/06/2026
Ericsson<br /> Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling<br /> of Missing Values (CWE-230) vulnerability where an attacker continuously<br /> sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.
Severity CVSS v4.0: HIGH
Last modification:
08/06/2026

CVE-2026-11345

Publication date:
05/06/2026
An Improper Authentication vulnerability in the /api/Cdn/GetFile endpoint of linqi allows unauthenticated, remote attackers to bypass file access controls. The ValidateAnonFileAccess function incorrectly grants access if an &amp;#39;AnonFile&amp;#39; query parameter containing exactly 256 characters is provided. While this flaw allows bypassing the intended authorization check, the actual security impact is negligible; the exposed resources are strictly limited to minified JavaScript and CSS files that contain no sensitive data and are already publicly accessible via a standard CDN.
Severity CVSS v4.0: MEDIUM
Last modification:
05/06/2026

CVE-2026-11346

Publication date:
05/06/2026
A Server-Side Request Forgery (SSRF) vulnerability in the custom process creation feature of linqi allows an authenticated attacker to probe internal network components. By crafting a specific process containing an HTTP Request component, an attacker can force the server to send arbitrary HTTP requests. By observing the varying application responses (Success, Failed, or 504 Gateway Time-out), the attacker can determine the status of internal ports, leading to internal network reconnaissance.
Severity CVSS v4.0: MEDIUM
Last modification:
05/06/2026

CVE-2026-8914

Publication date:
05/06/2026
In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 through 1.09.1, due to unsafe calls to an eval function in rpc-profile, a vulnerability exists where a lower privileged user could perform command injection as the root user.
Severity CVSS v4.0: HIGH
Last modification:
05/06/2026

CVE-2026-50265

Publication date:
05/06/2026
Rejected reason: This CVE ID was assigned as a duplicate of CVE-2026-50292
Severity CVSS v4.0: Pending analysis
Last modification:
08/06/2026

CVE-2026-21038

Publication date:
05/06/2026
Improper input validation in Samsung Android USB Driver for Windows prior to version 1.9.5.0 allows local attacker to access out-of-bounds memory.
Severity CVSS v4.0: MEDIUM
Last modification:
30/06/2026

CVE-2026-21037

Publication date:
05/06/2026
Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege.
Severity CVSS v4.0: MEDIUM
Last modification:
30/06/2026

CVE-2026-21035

Publication date:
05/06/2026
Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive information.
Severity CVSS v4.0: MEDIUM
Last modification:
30/06/2026