Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-5657

Publication date:
30/04/2026
iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Severity CVSS v4.0: Pending analysis
Last modification:
01/05/2026

CVE-2026-5655

Publication date:
30/04/2026
SDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 allows denial of service
Severity CVSS v4.0: Pending analysis
Last modification:
01/05/2026

CVE-2026-5654

Publication date:
30/04/2026
AMR-NB codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Severity CVSS v4.0: Pending analysis
Last modification:
01/05/2026

CVE-2026-5653

Publication date:
30/04/2026
DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Severity CVSS v4.0: Pending analysis
Last modification:
01/05/2026

CVE-2026-5408

Publication date:
30/04/2026
BT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Severity CVSS v4.0: Pending analysis
Last modification:
01/05/2026

CVE-2026-5407

Publication date:
30/04/2026
SMB2 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Severity CVSS v4.0: Pending analysis
Last modification:
01/05/2026

CVE-2026-5409

Publication date:
30/04/2026
Monero protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Severity CVSS v4.0: Pending analysis
Last modification:
01/05/2026

CVE-2026-41226

Publication date:
30/04/2026
Open redirect vulnerability exists in Multiple laser printers and MFPs which implement Ricoh Web Image Monitor. When accessing a specially crafted URL, the user may be redirected to an arbitrary website. As a result, the user may become a victim of a phishing attack.
Severity CVSS v4.0: MEDIUM
Last modification:
01/05/2026

CVE-2026-42511

Publication date:
30/04/2026
The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is subsequently re-parsed by dhclient, e.g., after a system restart, an attacker-controlled field from the lease is passed to dhclient-script(8), which evaluates it.<br /> <br /> A rogue DHCP server may be able to execute arbirary code as root on a system running dhclient.
Severity CVSS v4.0: Pending analysis
Last modification:
01/05/2026

CVE-2026-5406

Publication date:
30/04/2026
FC-SWILS protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Severity CVSS v4.0: Pending analysis
Last modification:
01/05/2026

CVE-2026-5402

Publication date:
30/04/2026
TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution
Severity CVSS v4.0: Pending analysis
Last modification:
01/05/2026

CVE-2026-5401

Publication date:
30/04/2026
AFP Spotlight protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Severity CVSS v4.0: Pending analysis
Last modification:
01/05/2026