Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-85479

Publication date:
09/10/2026
The STTP-based data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and exchange data with it.
Severity CVSS v4.0: MEDIUM
Last modification:
09/10/2026

CVE-2026-108063

Publication date:
09/10/2026
A flaw was found in libhangul. When parsing Hanja dictionary files, the library fails to verify that an entry contains a valid value alongside its key. By providing a specially crafted dictionary file to an application that queries it, an attacker can trigger an unexpected application crash, resulting in a Denial of Service (DoS).
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2026

CVE-2026-107785

Publication date:
09/10/2026
Crux Agent from 1.9.0 before 2.0.3 uses the full SKA bilocation key as the WireGuard preshared key. When a peering session negotiates use of SHA-512, the key produced is 64 bytes instead of the 32 bytes WireGuard requires. The agent does not validate this size; instead it attempts to use the `wg set` command to update the live tunnel, and write the invalid key to the WireGuard configuration file. The update fails, so the live tunnel keeps using its previous preshared key until the tunnel is shut down. The tunnel will fail to start when restarted.<br /> <br /> <br /> <br /> For a peer which has never successfully negotiated a 32-byte bilocation key in a Crux C2 organization which has the "Enforce SKA Use" setting turned off, no preshared key will be set for the tunnel. Therefore, an attacker who is able to intercept and store the peer&amp;#39;s traffic, and has access (or will have access) to a cryptographically relevant quantum computer, will be able to decrypt the tunnel.
Severity CVSS v4.0: MEDIUM
Last modification:
09/10/2026

CVE-2026-106581

Publication date:
09/10/2026
Before 4.92.0, Docker Desktop for Windows did not verify the signature of a package supplied to Docker Desktop Installer.exe install -package. An attacker able to provide a crafted package and convince a user to approve the Docker-signed UAC prompt could execute attacker-controlled installer actions as LocalSystem.
Severity CVSS v4.0: HIGH
Last modification:
09/10/2026

CVE-2026-105281

Publication date:
09/10/2026
The internal data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and retrieve the complete device and measurement topology of the system.
Severity CVSS v4.0: HIGH
Last modification:
09/10/2026

CVE-2026-104629

Publication date:
09/10/2026
A component loading mechanism in openPDC and openHistorian will construct and run any specified type, which may be an invalid component to load. An attacker with an authenticated user account and the ability to place a file on the host filesystem can use this to run arbitrary constructor code, and this code runs with the privileges of the affected service account.
Severity CVSS v4.0: HIGH
Last modification:
09/10/2026

CVE-2026-101022

Publication date:
09/10/2026
A Modbus connection feature on openPDC accepts a caller-specified destination address and port with no restriction on which internal hosts may be targeted. An authenticated user can attempt connections to arbitrary internal network destinations, revealing which destinations are reachable. With repeated attempts, an attacker may be able to map the internal network.
Severity CVSS v4.0: MEDIUM
Last modification:
09/10/2026

CVE-2026-100730

Publication date:
09/10/2026
A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on systems without Windows Authentication, this is reachable by an unauthenticated network attacker. This allows an attacker to trigger deserialization of an arbitrary object graph, which could allow remote code execution under the privileges of the affected service account.
Severity CVSS v4.0: CRITICAL
Last modification:
09/10/2026

CVE-2026-96396

Publication date:
09/10/2026
The Affinity by Canva application for macOS before 3.3.1 (October 2026 release) did not safely calculate the size of an image buffer when generating QuickLook thumbnails and previews of Affinity document files, leading to an integer overflow and a heap-based buffer overflow. A threat actor could craft an Affinity document that, when displayed or previewed by a user in Finder, could corrupt heap memory and cause the thumbnail or preview extension to crash.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2026

CVE-2026-94061

Publication date:
09/10/2026
Improper Neutralization of Input During Web Page Generation (&amp;#39;Cross-site Scripting&amp;#39;) vulnerability in Designthemes Whistle - Sports Club whistle-sports-club allows Reflected XSS.This issue affects Whistle - Sports Club: from n/a through 4.2.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2026

CVE-2026-96393

Publication date:
09/10/2026
The Affinity by Canva app before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing Affinity document files, leading to an out-of-bounds pointer dereference. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could result in an application crash.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2026

CVE-2026-96394

Publication date:
09/10/2026
The Affinity by Canva application for macOS before 3.3.1 (October 2026 release) did not validate image dimensions against the size of the pixel data when generating QuickLook thumbnails and previews of Affinity document files, leading to an out-of-bounds heap read. A threat actor could craft an Affinity document that, when displayed or previewed by a user in Finder, could disclose the contents of adjacent heap memory in the rendered thumbnail or preview image, or cause the thumbnail or preview extension to crash.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2026