Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-55995

Publication date:
29/07/2026
A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS.<br /> <br /> <br /> <br /> <br /> <br /> <br /> This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.
Severity CVSS v4.0: HIGH
Last modification:
29/07/2026

CVE-2026-16751

Publication date:
29/07/2026
Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an authenticated attacker configured as a victim&amp;#39;s emergency contact to bypass the configured recovery waiting period and take over the victim&amp;#39;s account via a crafted `approve-recovery` API request.
Severity CVSS v4.0: Pending analysis
Last modification:
29/07/2026

CVE-2026-18174

Publication date:
29/07/2026
@fastify/forwarded resolves client addresses from the X-Forwarded-For header. In versions before 3.0.2, when the header contains two or more comma separated entries, the parser trims only space characters and does not strip horizontal tabs, even though RFC 7230 defines optional whitespace as both space and tab. As a result, an entry padded with a tab keeps the literal tab in the resolved address string. Applications that make exact string match security decisions on the resolved client IP, such as an allowlist, a blocklist, a per IP rate limit key, or audit log correlation, can be evaded because the tab corrupted string no longer matches the expected value. This does not cross the trust boundary, since a tab corrupted string is not a valid IP and cannot be mistaken for a trusted proxy. The issue is fixed in @fastify/forwarded 3.0.2.
Severity CVSS v4.0: Pending analysis
Last modification:
29/07/2026

CVE-2026-65944

Publication date:
29/07/2026
Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI
Severity CVSS v4.0: Pending analysis
Last modification:
29/07/2026

CVE-2026-65946

Publication date:
29/07/2026
Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI
Severity CVSS v4.0: Pending analysis
Last modification:
29/07/2026

CVE-2026-65943

Publication date:
29/07/2026
Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI
Severity CVSS v4.0: Pending analysis
Last modification:
29/07/2026

CVE-2026-65891

Publication date:
29/07/2026
Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE)
Severity CVSS v4.0: Pending analysis
Last modification:
29/07/2026

CVE-2026-65885

Publication date:
29/07/2026
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox
Severity CVSS v4.0: CRITICAL
Last modification:
29/07/2026

CVE-2026-65884

Publication date:
29/07/2026
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox
Severity CVSS v4.0: CRITICAL
Last modification:
29/07/2026

CVE-2026-50641

Publication date:
29/07/2026
Streamsoft Business Intelligence (BI) stores users&amp;#39; passwords in plaintext form in the database<br /> <br /> This issue was fixed in version 6.8.0.0, users were also requested to change their password on the first login.
Severity CVSS v4.0: HIGH
Last modification:
29/07/2026

CVE-2026-44944

Publication date:
29/07/2026
An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket.<br /> <br /> <br /> <br /> <br /> <br /> <br /> This issue affects open-iscsi: from ? through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.
Severity CVSS v4.0: HIGH
Last modification:
29/07/2026

CVE-2026-44943

Publication date:
29/07/2026
An Improper Limitation of a Pathname to a Restricted Directory (&amp;#39;Path Traversal&amp;#39;) vulnerability in open-iscsi allows remote MITM attackers  to create root-owned files outside the database and inject lines into the record.<br /> <br /> <br /> <br /> <br /> <br /> <br /> This issue affects open-iscsi: from through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.
Severity CVSS v4.0: MEDIUM
Last modification:
29/07/2026