Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-34194

Publication date:
08/06/2026
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of a mapping state maintained for a sparse memory allocation.<br /> <br /> <br /> <br /> The product accidentally refers to the wrong memory due to the semantics of how math operations are implicitly scaled across buffers of different sizes.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-34356

Publication date:
08/06/2026
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie*<br /> <br /> This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.<br /> <br /> Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-36786

Publication date:
08/06/2026
Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the list1 parameter of the fromDhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-34355

Publication date:
08/06/2026
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend.<br /> Users are recommended to upgrade to version 2.4.68, which fixes this issue.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-11523

Publication date:
08/06/2026
A flaw has been found in Tenda W20E 15.11.0.6. This issue affects the function formPortalAuth of the file /goform/PortalAuth of the component Web Management Interface. Executing a manipulation of the argument gotoUrl can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.
Severity CVSS v4.0: HIGH
Last modification:
23/07/2026

CVE-2026-11524

Publication date:
08/06/2026
A vulnerability has been found in Tenda W20E 15.11.0.6. Impacted is the function modifyWifiFilterRules of the file /goform/modifyWifiFilterRules of the component Web Management Interface. The manipulation of the argument wifiFilterListRemark leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity CVSS v4.0: HIGH
Last modification:
23/07/2026

CVE-2026-11528

Publication date:
08/06/2026
A vulnerability was found in Tenda AC18 15.03.05.05. The affected element is the function sub_45304 of the file /goform/getRebootStatus of the component Web Management Interface. The manipulation of the argument callback results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.
Severity CVSS v4.0: HIGH
Last modification:
23/07/2026

CVE-2026-11529

Publication date:
08/06/2026
A vulnerability was determined in designcomputer mysql-mcp-server up to 0.2.2. The impacted element is the function read_resource of the file src/mysql_mcp_server/server.py of the component mysql URI Handler. This manipulation of the argument uri_str causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.3.0 is sufficient to resolve this issue. Patch name: 080bef9a96d625ce0dfbde573a08b93497871981. Upgrading the affected component is advised.
Severity CVSS v4.0: LOW
Last modification:
23/07/2026

CVE-2026-22164

Publication date:
08/06/2026
Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory.<br /> <br /> <br /> <br /> By creating resources of certain types and presenting a set of parameters to the affected interface the exploit can be used to corrupt kernel memory.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-29167

Publication date:
08/06/2026
Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration<br /> <br /> This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.<br /> <br /> Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-11522

Publication date:
08/06/2026
A vulnerability was detected in Tenda W20E 15.11.0.6. This vulnerability affects the function formSetPortMirror of the file /goform/setPortMirror. Performing a manipulation of the argument portMirrorMirroredPorts results in stack-based buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used.
Severity CVSS v4.0: HIGH
Last modification:
23/07/2026

CVE-2020-37248

Publication date:
08/06/2026
OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account credentials in cleartext.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026