Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-34907

Publication date:
02/06/2026
Wirtualna Uczelnia is vulnerable to Reflected Cross‑Site Scripting (XSS) due to insecure handling of the locale parameter across multiple endpoints. An attacker can craft a malicious URL with JavaScript embedded in the locale parameter and send it to a victim. When the victim opens the link, the injected script will be executed in their browser.<br /> <br /> <br /> This issue affects Wirtualna Uczelnia versions up to wu#2016.437.295#0#20260327_105545
Severity CVSS v4.0: MEDIUM
Last modification:
22/07/2026

CVE-2026-34906

Publication date:
02/06/2026
Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to perform Remote Code Execution (RCE). In the endpoint redirectToUrl and parameter redirectUrlParameter, insufficient input validation permits injection of arbitrary template expressions that are executed on the server. Successful exploitation can allow an attacker to run remote commands, including establishing a reverse shell.<br /> <br /> This issue affects Wirtualna Uczelnia versions up to wu#2016.437.295#0#20260327_105545
Severity CVSS v4.0: CRITICAL
Last modification:
22/07/2026

CVE-2025-53345

Publication date:
02/06/2026
Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress Thim Core.<br /> <br /> This issue affects Thim Core: from n/a through 2.3.3.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2025-53346

Publication date:
02/06/2026
Missing Authorization vulnerability in ThimPress Thim Core allows Exploiting Incorrectly Configured Access Control Security Levels.<br /> <br /> This issue affects Thim Core: from n/a through 2.3.3.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-10549

Publication date:
02/06/2026
LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP credentials to bypass group membership checks resulting in unauthorized access to the database.
Severity CVSS v4.0: MEDIUM
Last modification:
22/07/2026

CVE-2025-52759

Publication date:
02/06/2026
Improper Neutralization of Input During Web Page Generation (&amp;#39;Cross-site Scripting&amp;#39;) vulnerability in UnboundStudio Accordion FAQ allows Reflected XSS.<br /> <br /> This issue affects Accordion FAQ: from n/a through 2.2.1.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2025-52766

Publication date:
02/06/2026
Missing Authorization vulnerability in Printeers Printeers Print &amp; Ship allows Exploiting Incorrectly Configured Access Control Security Levels.<br /> <br /> This issue affects Printeers Print &amp; Ship: from n/a through 1.17.0.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2025-53209

Publication date:
02/06/2026
Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation.<br /> <br /> This issue affects Masteriyo LMS PRO: from n/a through 2.20.0.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2025-53302

Publication date:
02/06/2026
Missing Authorization vulnerability in Anton Shevchuk Constructor allows Accessing Functionality Not Properly Constrained by ACLs.<br /> <br /> This issue affects Constructor: from n/a through 1.6.5.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-9730

Publication date:
02/06/2026
The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the gmz_comment_settings_save function. This makes it possible for unauthenticated attackers to modify the plugin&amp;#39;s comment-display setting via a forged request via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-9234

Publication date:
02/06/2026
The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.4.1. This is due to missing capability checks and nonce verification on the admin_post_settings_save_woo-jtl-connector action (handled by JtlConnectorAdmin::save()) and on the wp_ajax_downloadJTLLogs and wp_ajax_clearJTLLogs AJAX actions (handled by the global downloadJTLLogs() and clearJTLLogs() functions). This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify arbitrary plugin settings, download a ZIP archive of the connector&amp;#39;s developer log files, and delete those log files.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-9599

Publication date:
02/06/2026
The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on the admin_init function. This makes it possible for unauthenticated attackers to modify the plugin&amp;#39;s settings, including the tectite_forms_button option, via a forged request via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026