Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-51380

Publication date:
15/07/2026
Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of Service (DoS) or potentially execute remote code via the /cgi-bin/UploadCfg endpoint
Severity CVSS v4.0: Pending analysis
Last modification:
16/07/2026

CVE-2026-52888

Publication date:
15/07/2026
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.59 and earlier, NocoBase @nocobase/plugin-collection-sql used the checkSQL() function in packages/plugins/@nocobase/plugin-collection-sql/src/server/utils.ts with an incomplete keyword blacklist that did not restrict PostgreSQL system catalog tables such as pg_shadow, pg_roles, and pg_stat_activity, allowing an admin-role user to read password hashes and database metadata through the SQL Collection feature. This vulnerability is fixed in 2.1.0-alpha.46.
Severity CVSS v4.0: Pending analysis
Last modification:
16/07/2026

CVE-2026-55398

Publication date:
15/07/2026
CVE-2026-55398<br /> is a memory management vulnerability in Secure Access clients and servers prior<br /> to 14.55. Attackers with intimate knowledge of and total control over the<br /> tunnel protocol can create a non-persistent DoS against the server.
Severity CVSS v4.0: MEDIUM
Last modification:
16/07/2026

CVE-2026-54052

Publication date:
15/07/2026
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp&amp;#39;s local workflow version history backups were not isolated per tenant, allowing an authenticated tenant to read workflow version snapshots belonging to other tenants and delete or destroy other tenants&amp;#39; stored backups, including full node definitions, credential references, and authorization headers. This issue is fixed in version 2.56.1.
Severity CVSS v4.0: Pending analysis
Last modification:
18/07/2026

CVE-2026-52887

Publication date:
15/07/2026
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal() template string without escaping or parameter binding, allowing a signed-up authenticated user to run stacked PostgreSQL statements and potentially execute commands with COPY ... TO PROGRAM. This vulnerability is fixed in 2.0.61.
Severity CVSS v4.0: Pending analysis
Last modification:
20/07/2026

CVE-2026-49353

Publication date:
15/07/2026
9Router is an AI router &amp; token saver. In 0.4.45 and earlier, 9Router&amp;#39;s src/dashboardGuard.js local-only access gate used Host and Origin headers in isLocalRequest() to protect /api/mcp/*, /api/tunnel/*, and /api/cli-tools/*, allowing header spoofing in reverse proxy or tunnel deployments to reach MCP child process stdin paths.
Severity CVSS v4.0: Pending analysis
Last modification:
16/07/2026

CVE-2026-49352

Publication date:
15/07/2026
9Router is an AI router &amp; token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in src/app/api/auth/login/route.js, src/middleware.js, and later src/lib/auth/dashboardSession.js, allowing attackers to forge an auth_token cookie when JWT_SECRET was unset. This issue is fixed in version 0.4.44
Severity CVSS v4.0: Pending analysis
Last modification:
16/07/2026

CVE-2026-46339

Publication date:
15/07/2026
9Router is an AI router &amp; token saver. From 0.4.30 until 0.4.37, 9Router&amp;#39;s src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated registration of customPlugins through src/app/api/cli-tools/cowork-settings/route.js and command execution through the MCP bridge. This vulnerability is fixed in 0.4.37.
Severity CVSS v4.0: Pending analysis
Last modification:
16/07/2026

CVE-2026-33684

Publication date:
15/07/2026
WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded permission parameters in signUp API, which allows any user who can solve a CAPTCHA to self-grant elevated permissions during account registration. The set_api_signUp method in the API plugin accepts emailVerified, canUpload, canStream, and canCreateMeet parameters from user-supplied input and applies them to newly created accounts without verifying that the request was authenticated with a valid APISecret. By self-granting account attributes, attackers can mark their own accounts as email-verified without owning the address (bypassing email-gated functionality) and award themselves upload, streaming, and meeting-creation permissions, circumventing administrator access controls that intentionally restrict these capabilities for new users. This issue has been fixed in version 29.0
Severity CVSS v4.0: Pending analysis
Last modification:
16/07/2026

CVE-2026-33445

Publication date:
15/07/2026
CVE-2026-33445 is a memory management<br /> vulnerability in Secure Access servers prior to 14.55. Attackers with an<br /> intimate knowledge of and total control over the tunnel protocol can create a<br /> persistent DoS against the server.
Severity CVSS v4.0: HIGH
Last modification:
16/07/2026

CVE-2026-33444

Publication date:
15/07/2026
CVE-2026-33444 is a memory management<br /> vulnerability in Secure Access servers prior to 14.55. Attackers with intimate<br /> knowledge of and total control over the tunnel protocol can create a<br /> non-persistent DoS against the server.
Severity CVSS v4.0: MEDIUM
Last modification:
16/07/2026

CVE-2026-38753

Publication date:
15/07/2026
A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
Severity CVSS v4.0: Pending analysis
Last modification:
20/07/2026