Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-61964

Publication date:
06/08/2026
Unauthenticated Cross Site Scripting (XSS) in Ninja Tables
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2026

CVE-2026-61982

Publication date:
06/08/2026
Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2026

CVE-2026-65502

Publication date:
06/08/2026
Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2026

CVE-2026-65504

Publication date:
06/08/2026
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2026

CVE-2026-65507

Publication date:
06/08/2026
Unauthenticated Privilege Escalation in AIWU
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2026

CVE-2026-65508

Publication date:
06/08/2026
Unauthenticated SQL Injection in Simply Schedule Appointments
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2026

CVE-2026-61961

Publication date:
06/08/2026
Unauthenticated Cross Site Scripting (XSS) in EmbedPress
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2026

CVE-2026-61959

Publication date:
06/08/2026
Subscriber Cross Site Scripting (XSS) in Business Directory
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2026

CVE-2026-54489

Publication date:
06/08/2026
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity.
Severity CVSS v4.0: Pending analysis
Last modification:
07/08/2026

CVE-2026-53975

Publication date:
06/08/2026
OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UI_PASSWORD is not configured, matching the default Docker deployment, enabling attackers to execute arbitrary OS commands as the application user and retrieve full command output including stdout, stderr, and exit code from the server response.
Severity CVSS v4.0: CRITICAL
Last modification:
06/08/2026

CVE-2026-53976

Publication date:
06/08/2026
OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an absolute path, bypassing the workspace boundary check in resolveReadPathFromContext. Attackers can exploit the vacuous isPathWithinRoot guard to read sensitive files such as the JWT signing secret, SSH private keys, API credentials, and environment variables, enabling full authentication bypass by forging session cookies on password-protected deployments.
Severity CVSS v4.0: CRITICAL
Last modification:
06/08/2026

CVE-2026-28183

Publication date:
06/08/2026
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2026