Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-54729

Publication date:
31/07/2026
DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost as safe when DNS resolver 1.1.1.1 returns NXDOMAIN because dns.resolve4 yields no address and no dns.lookup fallback occurs, allowing server-side request forgery. This issue is fixed in version 1.0.5.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-54725

Publication date:
31/07/2026
vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and MutateSecret call newVaultClient in pkg/webhook/webhook.go, and vault.security.banzaicloud.io/vault-serviceaccount can cause a ServiceAccount JWT to be sent to an attacker-controlled Vault address. This issue is fixed in version 1.23.1.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-54737

Publication date:
31/07/2026
@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursively merges user-supplied objects without filtering proto, constructor, and prototype, allowing properties to be written to Object.prototype. This issue is fixed in version 2.0.5.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-55100

Publication date:
31/07/2026
hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query strings instead of using encodeURIComponent() and URLSearchParams, allowing path traversal and query parameter injection. This issue is fixed in version 0.5.2.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-34490

Publication date:
31/07/2026
Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data.<br /> <br /> This issue affects XAAP Application: before 1.53.
Severity CVSS v4.0: MEDIUM
Last modification:
31/07/2026

CVE-2026-34495

Publication date:
31/07/2026
Improper neutralization of input during web page generation (&amp;#39;cross-site scripting&amp;#39;) vulnerability in Johnson Controls FM Systems Employee allows Stored XSS.<br /> <br /> This issue affects FM Systems Employee: before 2025.3.1.
Severity CVSS v4.0: MEDIUM
Last modification:
31/07/2026

CVE-2026-34497

Publication date:
31/07/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS).<br /> <br /> This issue affects FM Systems Employee: before 2025.3.1.
Severity CVSS v4.0: MEDIUM
Last modification:
31/07/2026

CVE-2026-21662

Publication date:
31/07/2026
Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files.<br /> <br /> This issue affects FM Systems Employee: before 2025.3.1.
Severity CVSS v4.0: MEDIUM
Last modification:
31/07/2026

CVE-2026-67822

Publication date:
31/07/2026
Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled &amp;#39;GO&amp;#39; and &amp;#39;index&amp;#39; parameters into a 64-byte stack buffer without length restriction, leading to stack overflow.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-58047

Publication date:
31/07/2026
HTTP Smuggling in cPanel allows potential leak of credentials.
Severity CVSS v4.0: MEDIUM
Last modification:
31/07/2026

CVE-2026-58048

Publication date:
31/07/2026
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
Severity CVSS v4.0: CRITICAL
Last modification:
31/07/2026

CVE-2026-54707

Publication date:
31/07/2026
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files setting in cli/onionshare_cli/web/receive_mode.py, where ReceiveModeRequest._get_file_stream() writes multipart file[] data to disk despite the text-only setting. This issue is fixed in version 2.6.4.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026