Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-60135

Publication date:
24/07/2026
An attacker can modify data that should be restricted to read‑only access.
Severity CVSS v4.0: HIGH
Last modification:
30/07/2026

CVE-2026-61886

Publication date:
24/07/2026
Weintek cMT3092X HMI stores user account passwords in plaintext.
Severity CVSS v4.0: HIGH
Last modification:
30/07/2026

CVE-2026-61892

Publication date:
24/07/2026
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
Severity CVSS v4.0: HIGH
Last modification:
30/07/2026

CVE-2026-16280

Publication date:
24/07/2026
An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical memory, resulting in memory corruption or information disclosure.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-60134

Publication date:
24/07/2026
Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
Severity CVSS v4.0: HIGH
Last modification:
30/07/2026

CVE-2026-55985

Publication date:
24/07/2026
The web management interface in <br /> Tycon Systems TPDIN-Monitor-WEB2<br /> <br /> stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.
Severity CVSS v4.0: MEDIUM
Last modification:
30/07/2026

CVE-2026-61884

Publication date:
24/07/2026
The web management interface of Tycon Systems TPDIN-Monitor-WEB2<br /> <br />  does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, device reboot, remote access service configuration, and network settings, which could allow an attacker to disrupt connected infrastructure or cause physical damage to equipment.
Severity CVSS v4.0: CRITICAL
Last modification:
30/07/2026

CVE-2025-71408

Publication date:
24/07/2026
NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lookup and executes arbitrary code including OS commands via the os module.
Severity CVSS v4.0: HIGH
Last modification:
30/07/2026

CVE-2026-66041

Publication date:
24/07/2026
FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution.
Severity CVSS v4.0: HIGH
Last modification:
07/08/2026

CVE-2026-66040

Publication date:
24/07/2026
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution.
Severity CVSS v4.0: HIGH
Last modification:
07/08/2026

CVE-2026-66039

Publication date:
24/07/2026
FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution.
Severity CVSS v4.0: HIGH
Last modification:
07/08/2026

CVE-2026-66038

Publication date:
24/07/2026
FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame&amp;#39;s worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services.
Severity CVSS v4.0: HIGH
Last modification:
07/08/2026