Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-16531

Publication date:
30/07/2026
An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-16524

Publication date:
30/07/2026
A command injection flaw in PCP&amp;#39;s linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric.<br /> This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2026

CVE-2026-16526

Publication date:
30/07/2026
A flaw in the PCP linux_sockets module exposes an unsecured internal connection.<br /> An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2026

CVE-2026-16529

Publication date:
30/07/2026
A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2026

CVE-2026-16527

Publication date:
30/07/2026
An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
Severity CVSS v4.0: Pending analysis
Last modification:
07/08/2026

CVE-2026-15255

Publication date:
30/07/2026
The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the identity being requested before returning front-end form submissions, allowing unauthenticated attackers to read other users&amp;#39; form submission data, including personal information.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-15257

Publication date:
30/07/2026
The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing action, allowing unauthenticated attackers to overwrite other users&amp;#39; form submissions and the profile fields of the associated non-administrator WordPress accounts.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-15382

Publication date:
30/07/2026
The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site&amp;#39;s custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site&amp;#39;s custom icon fonts with a single request.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-14923

Publication date:
30/07/2026
The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a REST route that creates and updates posts, because of an operator-precedence flaw in its authorization check. An authenticated user holding only the post-editing capability (such as a Contributor) can create, publish, and overwrite arbitrary Pages, including modifying content authored by higher-privileged users.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-15240

Publication date:
30/07/2026
The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the operator who initiated it, allowing a lower-privileged account that an operator is currently switched into to be resolved as that operator and to switch into any permitted account, including an administrator, resulting in full account takeover.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-15250

Publication date:
30/07/2026
The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated visitor can set through its public booking funnel, allowing an unauthenticated user to assign a privileged booking field such as the approval status and thereby bypass the site&amp;#39;s booking approval workflow.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-15252

Publication date:
30/07/2026
The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX handlers, allowing any authenticated user such as a Subscriber to invoke the site&amp;#39;s Google Indexing API integration, submitting or removing the site&amp;#39;s URLs from Google&amp;#39;s index and consuming its indexing quota.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026