Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-66339

Publication date:
24/07/2026
A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information disclosure.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-66337

Publication date:
24/07/2026
A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client application to crash or disclose sensitive heap memory.
Severity CVSS v4.0: Pending analysis
Last modification:
27/07/2026

CVE-2026-60135

Publication date:
24/07/2026
An attacker can modify data that should be restricted to read‑only access.
Severity CVSS v4.0: HIGH
Last modification:
30/07/2026

CVE-2026-61886

Publication date:
24/07/2026
Weintek cMT3092X HMI stores user account passwords in plaintext.
Severity CVSS v4.0: HIGH
Last modification:
30/07/2026

CVE-2026-61892

Publication date:
24/07/2026
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
Severity CVSS v4.0: HIGH
Last modification:
30/07/2026

CVE-2026-16280

Publication date:
24/07/2026
An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical memory, resulting in memory corruption or information disclosure.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-60134

Publication date:
24/07/2026
Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
Severity CVSS v4.0: HIGH
Last modification:
30/07/2026

CVE-2026-55985

Publication date:
24/07/2026
The web management interface in <br /> Tycon Systems TPDIN-Monitor-WEB2<br /> <br /> stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.
Severity CVSS v4.0: MEDIUM
Last modification:
30/07/2026

CVE-2026-61884

Publication date:
24/07/2026
The web management interface of Tycon Systems TPDIN-Monitor-WEB2<br /> <br />  does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, device reboot, remote access service configuration, and network settings, which could allow an attacker to disrupt connected infrastructure or cause physical damage to equipment.
Severity CVSS v4.0: CRITICAL
Last modification:
30/07/2026

CVE-2025-71408

Publication date:
24/07/2026
NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lookup and executes arbitrary code including OS commands via the os module.
Severity CVSS v4.0: HIGH
Last modification:
30/07/2026

CVE-2026-66040

Publication date:
24/07/2026
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution.
Severity CVSS v4.0: HIGH
Last modification:
29/07/2026

CVE-2026-66041

Publication date:
24/07/2026
FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution.
Severity CVSS v4.0: HIGH
Last modification:
29/07/2026