Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-55728

Publication date:
24/07/2026
Stack-based Buffer Overflow (CWE-121) in `/usr/bin/ltsudo` `cmd_ipaddr_conflict` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to trigger a SUID-root process abort or potentially elevate privileges via an overly long interface-name argument.
Severity CVSS v4.0: LOW
Last modification:
27/07/2026

CVE-2026-49326

Publication date:
24/07/2026
Missing Authorization vulnerability in Apache HBase thrift and rest delegation service.<br /> <br /> A scan operation in thrift/rest service has 3 steps, open, fetch(possible multiple times), close.<br /> The open step will return an id which will be passed back to server for identifying the scanner instances stored at server side.<br /> We missed the owner check in fetch and close steps which means a user can fetch rows from the scanner which is opened by other users, and close scanners which belongs to other users.<br /> <br /> This issue affects Apache HBase:from 3.0.0-alpha-1 through 3.0.0-beta-1, from 2.6.0 through 2.6.5, from 2.5.0 through 2.5.14, through 2.4.*.<br /> <br /> Users are recommended to upgrade to version 3.0.0-beta-2, 2.6.6 and 2.5.15, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2026

CVE-2026-17059

Publication date:
24/07/2026
A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission to view individual users when listing members of a role. This allows a restricted administrator to see private information, such as names and email addresses, for users they should not be able to access.
Severity CVSS v4.0: Pending analysis
Last modification:
24/07/2026

CVE-2026-16801

Publication date:
24/07/2026
Improper control of generation of code (&amp;#39;Code Injection&amp;#39;) in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the variables configuration file.
Severity CVSS v4.0: Pending analysis
Last modification:
29/07/2026

CVE-2026-16802

Publication date:
24/07/2026
Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when no vault is selected.
Severity CVSS v4.0: Pending analysis
Last modification:
29/07/2026

CVE-2026-16798

Publication date:
24/07/2026
Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user&amp;#39;s stored OAuth refresh token via job read responses that fail to strip the refresh token.
Severity CVSS v4.0: Pending analysis
Last modification:
29/07/2026

CVE-2026-16799

Publication date:
24/07/2026
Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization checks.
Severity CVSS v4.0: Pending analysis
Last modification:
29/07/2026

CVE-2026-16800

Publication date:
24/07/2026
Improper control of generation of code (&amp;#39;Code Injection&amp;#39;) in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via crafted schedule parameter names concatenated into a script invocation.
Severity CVSS v4.0: Pending analysis
Last modification:
29/07/2026

CVE-2026-12504

Publication date:
24/07/2026
Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a local attacker to authenticate as a uid=0 account without a password and obtain a root shell via an `/etc/passwd` entry with an empty password field.
Severity CVSS v4.0: HIGH
Last modification:
27/07/2026

CVE-2026-12502

Publication date:
24/07/2026
Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to reset the password of any LARM user (including the `larmapp` service account) via the `set-passwd` subcommand.
Severity CVSS v4.0: HIGH
Last modification:
27/07/2026

CVE-2026-12503

Publication date:
24/07/2026
Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `larmapp` attacker to make `/etc/passwd` writable by the `larmapp` group (leading to root privilege escalation) via a symlink attack on `/etc/lighttpd/ssl/server.pem`.
Severity CVSS v4.0: CRITICAL
Last modification:
27/07/2026

CVE-2026-12496

Publication date:
24/07/2026
Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to execute arbitrary JavaScript in an administrator&amp;#39;s browser (session hijacking, credential theft, device reconfiguration) via a crafted `User-Agent` header in a `POST /da` request.
Severity CVSS v4.0: HIGH
Last modification:
27/07/2026