Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-49397

Publication date:
12/06/2026
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.0 to before version 2.0.14, private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data. This issue has been patched in version 2.0.14.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2026

CVE-2026-53519

Publication date:
12/06/2026
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to version 2.0.13, fallbackToFrontend in the dashboard's NoRoute handler treats any URL whose raw string starts with /dashboard as an admin-frontend asset request. The check uses strings.HasPrefix, not a path-segment match, so the input /dashboard../data/config.yaml is accepted; strings.TrimPrefix leaves ../data/config.yaml; and path.Join("admin-dist", "../data/config.yaml") normalizes to data/config.yaml — which os.Stat finds and http.ServeFile returns. No authentication required. This issue has been patched in version 2.0.13.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2026

CVE-2026-49396

Publication date:
12/06/2026
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.0.14, cross-site GET request can trigger stored cron commands on a victim's agents. This issue has been patched in version 2.0.14.
Severity CVSS v4.0: Pending analysis
Last modification:
13/06/2026

CVE-2026-34195

Publication date:
12/06/2026
Software installed and run as a non-privileged user may conduct intentional GPU sparse memory API calls to cause out of bounds write in the kernel.<br /> <br /> <br /> <br /> The product incorrectly indexes internal state when performing sparse allocation remapping.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2026

CVE-2026-41155

Publication date:
12/06/2026
An attacker could cooperatively pass data from one secure GPU process to another secure GPU process through shared secure memory allocations in the kernel module. Additionally, an attacker could disrupt the operation of another secure GPU process leading to image corruption / GPU hardware recovery.<br /> <br /> <br /> <br /> Sharing secure memory allocations among various GPU secure processes allows an attacker to corrupt shared resource affecting other users.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2026

CVE-2026-41157

Publication date:
12/06/2026
A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger an out-of-bound write in the GPU user-space driver, leading to memory corruption and possible browser/GPU process crash.<br /> <br /> <br /> <br /> The software computes a required memory size from untrusted input, but integer overflow can produce a value smaller than needed. Subsequent write operations may then occur past the intended memory boundary, corrupting adjacent memory and causing process instability or termination.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2026

CVE-2026-41158

Publication date:
12/06/2026
Software installed and run as a non-privileged user may conduct GPU system calls to write to arbitrary freed physical pages.<br /> <br /> <br /> <br /> Physical memory allocated and freed, without the deferred free mechanism can lead to those resources being used for read/write by the GPU after the kernel module has freed the resource.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2026

CVE-2026-46716

Publication date:
12/06/2026
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&amp;M tool. From version 1.4.0 to before version 2.0.8, a RoleMember user can create a scheduled cron task with Cover=CronCoverAll, Servers=[] and an arbitrary Command. At every tick of the scheduler, the dashboard pushes that command to every server in the global ServerShared map — including servers that belong to other tenants (admin&amp;#39;s servers, other members&amp;#39; servers). Each agent runs the command and returns the output, which is then sent to the attacker&amp;#39;s own NotificationGroup → attacker-controlled webhook. This issue has been patched in version 2.0.8.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2026

CVE-2026-46717

Publication date:
12/06/2026
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&amp;M tool. From version 1.4.0 to before version 2.0.8, nezha&amp;#39;s dashboard supports two user roles: RoleAdmin (Role==0) and RoleMember (Role==1). The notification routes POST /api/v1/notification and PATCH /api/v1/notification/:id are wired through commonHandler rather than adminHandler — so a RoleMember user can call them. These handlers synchronously Send() an HTTP request to a user-controlled URL and reflect the entire response body (no size limit) back to the caller on any non-2xx response. This issue has been patched in version 2.0.8.
Severity CVSS v4.0: Pending analysis
Last modification:
13/06/2026

CVE-2025-7010

Publication date:
12/06/2026
Stack overflow vulnerability due to uncontrolled recursion in Avast Antivirus when scanning a malformed PDF file may allow Denial-of-Service of the antivirus process.<br /> <br /> This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds before VPS 25021208.<br /> <br /> <br /> <br /> The affected scanning logic is delivered through a shared Gen Digital virus definition update stream. The same stream feeds the consumer antivirus products listed in this advisory and other Gen Digital products that embed the same engine. Mitigation flows through this update channel; installations at or above the listed build are not vulnerable regardless of which product consumes the stream.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2026

CVE-2025-7011

Publication date:
12/06/2026
Heap out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed zip file containing XML may allow Local Execution of Code or Denial-of-Service of the antivirus process.<br /> <br /> This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds from 25020100 before 25021208.<br /> <br /> <br /> <br /> The affected scanning logic is delivered through a shared Gen Digital virus definition update stream. The same stream feeds the consumer antivirus products listed in this advisory and other Gen Digital products that embed the same engine. Mitigation flows through this update channel; installations at or above the listed build are not vulnerable regardless of which product consumes the stream.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2026

CVE-2025-7017

Publication date:
12/06/2026
Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed Windows MSI file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process.<br /> <br /> This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.56.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2026