Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-48961

Publication date:
27/05/2026
IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.<br /> <br /> When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises &amp;#39;Undefined subroutine &amp;main::unpackValueQ&amp;#39; and the script exits with status 255.<br /> <br /> Library callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2026

CVE-2026-48962

Publication date:
27/05/2026
IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.<br /> <br /> _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.<br /> <br /> Arbitrary Perl in the output glob executes at the calling process&amp;#39;s privilege.
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2026

CVE-2026-48999

Publication date:
27/05/2026
Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access pages containing such malicious content, the scripts are automatically loaded and executed in the victim&amp;#39;s browser.Attackers can thereby steal user cookies, hijack session privileges, and tamper with page content.Since the malicious code is stored within the system, the attack scope is broad and the concealment is strong, making it frequently employed for data theft attacks.
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2026

CVE-2026-9022

Publication date:
27/05/2026
The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via &amp;#39;url&amp;#39; Block Attribute in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload must be published before it executes for site visitors, which requires an editor or administrator to approve and publish the contributor&amp;#39;s post.
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2026

CVE-2026-2253

Publication date:
27/05/2026
Hitachi Vantara Pentaho Data Integration &amp; Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external entities.
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2026

CVE-2026-2254

Publication date:
27/05/2026
Hitachi Vantara Pentaho Data Integration &amp; Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platform mail notfications.
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2026

CVE-2026-2255

Publication date:
27/05/2026
Hitachi Vantara Pentaho Data Integration &amp; Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those credentials to submit jobs under the same account through the backend API.
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2026

CVE-2025-15649

Publication date:
27/05/2026
IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.<br /> <br /> _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.<br /> <br /> The exception propagates out of IO::Uncompress::Unzip-&gt;new($file) where callers expect undef plus $UnzipError.
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2026

CVE-2026-9632

Publication date:
27/05/2026
A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of the file /goform/formGroupConfig of the component Web Management Interface. Executing a manipulation of the argument Profile can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.
Severity CVSS v4.0: HIGH
Last modification:
27/05/2026

CVE-2026-9608

Publication date:
27/05/2026
A vulnerability was determined in QianFox FoxCMS up to 1.2.6. The impacted element is an unknown function of the file /Tag/edit of the component Administrator Backend. Executing a manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Severity CVSS v4.0: LOW
Last modification:
27/05/2026

CVE-2026-9609

Publication date:
27/05/2026
A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The manipulation leads to weak password recovery. The attack can be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity CVSS v4.0: LOW
Last modification:
27/05/2026

CVE-2026-9627

Publication date:
27/05/2026
A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/setSysAdm of the component Web Management Interface. The manipulation of the argument sysAdmUser/sysAdmPass results in buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Severity CVSS v4.0: HIGH
Last modification:
27/05/2026