Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-13184

Publication date:
22/07/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-13181

Publication date:
22/07/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affected deployments.
Severity CVSS v4.0: Pending analysis
Last modification:
24/07/2026

CVE-2026-8152

Publication date:
22/07/2026
Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack.<br /> <br /> <br /> When Unblu Spark is deployed with com.unblu.identifier.siteEmbeddedSetup=true, it runs in the same origin as the host application. Any JavaScript injected through this vulnerability therefore executes with full access to the host application&amp;#39;s cookies, DOM, and same-origin APIs — an attacker can reach all resources of the host application, not just Unblu&amp;#39;s. This expanded blast radius is the reason on-premises deployments using this configuration are rated CRITICAL.
Severity CVSS v4.0: CRITICAL
Last modification:
22/07/2026

CVE-2026-44191

Publication date:
22/07/2026
A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts settings, allowing an attacker to inject shell separators. This can be triggered automatically during Language Server initialization or manually when executing a playbook. Successful exploitation leads to remote code execution (RCE) on the victim&amp;#39;s machine with the privileges of the Visual Studio Code user, potentially resulting in a complete system compromise.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-16270

Publication date:
22/07/2026
Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule can add an unsafe regex to a field. When someone provide the proper string it can result in a DoS attack.<br /> <br /> <br /> This issue was fixed in version 0.6.4.
Severity CVSS v4.0: MEDIUM
Last modification:
22/07/2026

CVE-2026-65602

Publication date:
22/07/2026
Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references (the allowlist was only enforced for HTTP serversTransport references). A low-privileged Kubernetes user in a namespace not listed in crossProviderNamespaces can set serversTransport: foo@file on an IngressRouteTCP service, causing Traefik to accept the forbidden cross-provider reference and use a file-provider TCPServersTransport — including privileged backend mTLS client certificates, SPIFFE identity, or PROXY-protocol settings. This is fixed in 3.6.23 and 3.7.7.
Severity CVSS v4.0: MEDIUM
Last modification:
22/07/2026

CVE-2026-65603

Publication date:
22/07/2026
The Grav Login plugin (grav-plugin-login) versions
Severity CVSS v4.0: HIGH
Last modification:
22/07/2026

CVE-2026-65601

Publication date:
22/07/2026
Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef, Traefik used the backend Service namespace instead of the HTTPRoute namespace. A low-privileged route author holding a ReferenceGrant for a cross-namespace Service could therefore bind a Traefik Middleware from the backend namespace without a separate grant for that middleware, potentially injecting trusted reverse-proxy identity headers into downstream requests. The issue is fixed in version 3.7.7.
Severity CVSS v4.0: MEDIUM
Last modification:
23/07/2026

CVE-2026-65600

Publication date:
22/07/2026
Traefik versions = v3.6.0 = v3.7.0
Severity CVSS v4.0: HIGH
Last modification:
23/07/2026

CVE-2026-65598

Publication date:
22/07/2026
n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node&amp;#39;s clone operation that allows authenticated users to bypass path restrictions by swapping a directory for a symlink after the path is validated but before the clone runs. This lets an attacker plant a crafted repository in the community node directory, which n8n loads as a custom node on the next restart, executing arbitrary JavaScript on the server. Both self-hosted and cloud instances are affected.
Severity CVSS v4.0: HIGH
Last modification:
27/07/2026

CVE-2026-65599

Publication date:
22/07/2026
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Google Service Account key, the full PEM private key was mistakenly placed in the JWT header&amp;#39;s kid field (intended only for a key identifier). Because JWT headers are Base64-encoded rather than encrypted, the private key could be recovered by anything that logged or inspected the JWT. An attacker who obtained the key could impersonate the service account and access or modify any Google Cloud resource it was authorized to use. Only instances using Google Service Account credentials are affected.
Severity CVSS v4.0: MEDIUM
Last modification:
27/07/2026

CVE-2026-65591

Publication date:
22/07/2026
n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator&amp;#39;s computed-member handler. An authenticated user with workflow create or modify permissions can craft a malicious expression to bypass the sanitizer and achieve host-level code execution as the n8n process. The legacy expression engine is the default in affected versions. Fixed in n8n 1.123.64, 2.29.8, and 2.30.1.
Severity CVSS v4.0: HIGH
Last modification:
27/07/2026