Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-24798

Publication date:
27/01/2026
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GaijinEntertainment DagorEngine (prog/3rdPartyLibs/miniupnpc modules). This vulnerability is associated with program files upnpreplyparse.C.<br /> <br /> This issue affects DagorEngine: through dagor_2025_01_15.
Severity CVSS v4.0: CRITICAL
Last modification:
15/04/2026

CVE-2026-24799

Publication date:
27/01/2026
Out-of-bounds Write, Buffer Copy without Checking Size of Input (&amp;#39;Classic Buffer Overflow&amp;#39;) vulnerability in davisking dlib (dlib/external/zlib modules). This vulnerability is associated with program files inflate.C.<br /> <br /> This issue affects dlib: before v19.24.9.
Severity CVSS v4.0: MEDIUM
Last modification:
15/04/2026

CVE-2026-24800

Publication date:
27/01/2026
Out-of-bounds Write, Buffer Copy without Checking Size of Input (&amp;#39;Classic Buffer Overflow&amp;#39;) vulnerability in tildearrow furnace (extern/zlib modules). This vulnerability is associated with program files inflate.C.
Severity CVSS v4.0: CRITICAL
Last modification:
15/04/2026

CVE-2026-24793

Publication date:
27/01/2026
Out-of-bounds Write, Buffer Copy without Checking Size of Input (&amp;#39;Classic Buffer Overflow&amp;#39;) vulnerability in azerothcore azerothcore-wotlk (deps/zlib modules). This vulnerability is associated with program files inflate.C.<br /> <br /> This issue affects azerothcore-wotlk: through v4.0.0.
Severity CVSS v4.0: CRITICAL
Last modification:
17/02/2026

CVE-2026-21720

Publication date:
27/01/2026
Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an unbuffered channel. Sustained traffic with random hashes keeps tripping this timeout, so goroutine count grows linearly, eventually exhausting memory and causing Grafana to crash on some systems.
Severity CVSS v4.0: Pending analysis
Last modification:
17/02/2026

CVE-2026-1464

Publication date:
27/01/2026
Integer Overflow or Wraparound vulnerability in MuntashirAkon AppManager (app/src/main/java/org/apache/commons/compress/archivers/tar modules). This vulnerability is associated with program files TarUtils.Java.<br /> <br /> This issue affects AppManager: before 4.0.4.
Severity CVSS v4.0: MEDIUM
Last modification:
15/04/2026

CVE-2026-1465

Publication date:
27/01/2026
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in anyrtcIO-Community anyRTC-RTMP-OpenSource (third_party/faad2-2.7/libfaad modules). This vulnerability is associated with program files bits.C, syntax.C.<br /> <br /> This issue affects anyRTC-RTMP-OpenSource: before 1.0.
Severity CVSS v4.0: HIGH
Last modification:
15/04/2026

CVE-2026-24344

Publication date:
27/01/2026
Multiple Buffer Overflows in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to cause a program crash and potential remote code execution
Severity CVSS v4.0: HIGH
Last modification:
15/04/2026

CVE-2026-21721

Publication date:
27/01/2026
The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2026

CVE-2025-14971

Publication date:
27/01/2026
The Link Invoice Payment for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the createPartialPayment and cancelPartialPayment functions in all versions up to, and including, 2.8.0. This makes it possible for unauthenticated attackers to create partial payments on any order or cancel any existing partial payment via ID enumeration.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2026-21408

Publication date:
27/01/2026
beat-access for Windows version 3.0.3 and prior contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with SYSTEM privileges.
Severity CVSS v4.0: MEDIUM
Last modification:
15/04/2026

CVE-2026-1361

Publication date:
27/01/2026
ASDA-Soft Stack-based Buffer Overflow Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
17/02/2026