Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-28116

Publication date:
02/06/2026
Improper Neutralization of Input During Web Page Generation (&amp;#39;Cross-site Scripting&amp;#39;) vulnerability in Emilia Projects Progress Planner allows Stored XSS.<br /> <br /> This issue affects Progress Planner: from n/a through 1.9.0.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-32685

Publication date:
02/06/2026
Path traversal vulnerability in Gleam&amp;#39;s handling of custom documentation pages allows arbitrary file read and file write outside the intended documentation output directory.<br /> <br /> The documentation.pages entries from gleam.toml are incorporated into filesystem paths without sufficient validation or confinement to the intended project and documentation output directories. The documentation.pages[].path field can be used to write generated documentation files outside the intended build/dev/docs// output directory. The documentation.pages[].source field can be used to read files outside the project directory and embed their contents into generated documentation output.<br /> <br /> An attacker who can convince a victim to run gleam docs build on an untrusted project, or with untrusted gleam.toml content, can cause local files readable by the victim to be included in generated documentation artifacts, and can cause generated documentation files to be written outside the intended docs output directory.<br /> <br /> This issue affects Gleam from 1.16.0 until 1.17.0.
Severity CVSS v4.0: MEDIUM
Last modification:
22/07/2026

CVE-2026-10621

Publication date:
02/06/2026
Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to properly validate and canonicalize file path during ZIP extraction, this can allow an attacker to write files outside the intended extraction directory.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-10622

Publication date:
02/06/2026
Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged functionality via exposed &amp;#39;/rest/* endpoints.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-10611

Publication date:
02/06/2026
An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with LdapAuth.mixedAuth=true and Security.require_otp=true, users authenticated through an authentication plugin, such as LDAP, may have their authenticated session established during the application beforeFilter phase before the normal login flow enforces the OTP challenge.<br /> <br /> <br /> <br /> As a result, an attacker with valid primary authentication credentials could bypass the required OTP step by authenticating through the plugin-backed login flow and then directly accessing another application URL instead of completing the OTP verification page. This allows access to the application as the affected user without providing a valid TOTP, HOTP, or email OTP code.<br /> <br /> <br /> <br /> The issue affects configurations where plugin-based authentication is enabled and OTP is expected to be mandatory. The fix ensures that OTP requirements are checked immediately after plugin authentication and before the user session is established, redirecting users to the appropriate OTP challenge when required.
Severity CVSS v4.0: HIGH
Last modification:
22/07/2026

CVE-2025-68886

Publication date:
02/06/2026
Improper Control of Filename for Include/Require Statement in PHP Program (&amp;#39;PHP Remote File Inclusion&amp;#39;) vulnerability in androThemes Cookiteer allows PHP Local File Inclusion.<br /> <br /> This issue affects Cookiteer: from n/a through 1.4.8.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2025-69369

Publication date:
02/06/2026
Improper Control of Filename for Include/Require Statement in PHP Program (&amp;#39;PHP Remote File Inclusion&amp;#39;) vulnerability in Axiomthemes Racquet allows PHP Local File Inclusion.<br /> <br /> This issue affects Racquet: from n/a through 1.12.0.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2025-58707

Publication date:
02/06/2026
Improper Control of Filename for Include/Require Statement in PHP Program (&amp;#39;PHP Remote File Inclusion&amp;#39;) vulnerability in Axiomthemes Spin allows PHP Local File Inclusion.<br /> <br /> This issue affects Spin: from n/a through 1.8.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2025-58897

Publication date:
02/06/2026
Improper Control of Filename for Include/Require Statement in PHP Program (&amp;#39;PHP Remote File Inclusion&amp;#39;) vulnerability in Axiomthemes Fermentio allows PHP Local File Inclusion.<br /> <br /> This issue affects Fermentio: from n/a through 1.5.0.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2019-25719

Publication date:
02/06/2026
Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0.3, and lower contain network message handling vulnerabilities that allow network-adjacent attackers to spoof or tamper with data and cause denial-of-service conditions. Attackers with access to an enabled Infinity network port or physical proximity to a wireless access point can modify device settings such as alarm states or alarm limits, and overwhelm the system with incoming data causing the device to reboot and lose network functionality.
Severity CVSS v4.0: HIGH
Last modification:
22/07/2026

CVE-2019-25717

Publication date:
02/06/2026
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection. Attackers can retrieve device internals, location information, and wired network configuration details from the exposed log files.
Severity CVSS v4.0: MEDIUM
Last modification:
22/07/2026

CVE-2026-8993

Publication date:
02/06/2026
D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom URL handlers that could be exploited to initiate full NTLM autentication or SMB connection to attacker infrastructure and to conduct SSRF (Server Side Request Forgery) attacks. User interaction is required as potential victim needs to open a specially crafted URL.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026