Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-39687

Publication date:
08/04/2026
Missing Authorization vulnerability in Rapid Car Check Rapid Car Check Vehicle Data free-vehicle-data-uk allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rapid Car Check Vehicle Data: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2026

CVE-2026-39688

Publication date:
08/04/2026
Missing Authorization vulnerability in Glowlogix WP Frontend Profile wp-front-end-profile allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Frontend Profile: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2026

CVE-2026-39689

Publication date:
08/04/2026
Missing Authorization vulnerability in eshipper eShipper Commerce eshipper-commerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects eShipper Commerce: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2026

CVE-2026-39675

Publication date:
08/04/2026
Missing Authorization vulnerability in webmuehle Court Reservation court-reservation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Court Reservation: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2026

CVE-2026-39676

Publication date:
08/04/2026
Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2026

CVE-2026-39677

Publication date:
08/04/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Emphires emphires allows PHP Local File Inclusion.This issue affects Emphires: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2026

CVE-2026-39678

Publication date:
08/04/2026
Missing Authorization vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pinpoint Booking System: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2026

CVE-2026-39679

Publication date:
08/04/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Freeio freeio allows PHP Local File Inclusion.This issue affects Freeio: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2026

CVE-2026-39680

Publication date:
08/04/2026
Missing Authorization vulnerability in MWP Development Diet Calorie Calculator diet-calorie-calculator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Diet Calorie Calculator: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2026

CVE-2026-39681

Publication date:
08/04/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Homeo homeo allows PHP Local File Inclusion.This issue affects Homeo: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2026

CVE-2026-39667

Publication date:
08/04/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jongmyoung Kim Korea SNS korea-sns allows DOM-Based XSS.This issue affects Korea SNS: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2026

CVE-2026-39668

Publication date:
08/04/2026
Missing Authorization vulnerability in g5theme Book Previewer for Woocommerce book-previewer-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Book Previewer for Woocommerce: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2026