Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-15189

Publication date:
09/07/2026
A security vulnerability has been detected in aerostackdev aerostack-mcp up to 6315dfde7df0a15aaf743f88d91347115e09ba23. Affected by this issue is the function upload_media of the component mcp-whatsapp. Such manipulation of the argument media_url leads to server-side request forgery. The attack may be launched remotely. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-11404

Publication date:
09/07/2026
Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating it against the length of received data. A remote, unauthenticated attacker can send a single crafted ClientHello with an oversized session id length to read past the receive buffer, crashing any HTTPS, MQTTS, or WSS service built on MG_TLS_BUILTIN.
Severity CVSS v4.0: HIGH
Last modification:
28/07/2026

CVE-2025-27462

Publication date:
09/07/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]<br /> <br /> <br /> The Windows PV drivers expose various facilities to userspace. Several<br /> of these have no security descriptor, and are therefore fully accessible<br /> to unprivileged users. These are:<br /> <br /> 1. XenCons, CVE-2025-27462<br /> 2. XenIface, CVE-2025-27463<br /> 3. XenBus, CVE-2025-27464
Severity CVSS v4.0: CRITICAL
Last modification:
09/07/2026

CVE-2025-27463

Publication date:
09/07/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. These are: 1. XenCons, CVE-2025-27462 2. XenIface, CVE-2025-27463 3. XenBus, CVE-2025-27464
Severity CVSS v4.0: CRITICAL
Last modification:
09/07/2026

CVE-2025-27464

Publication date:
09/07/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. These are: 1. XenCons, CVE-2025-27462 2. XenIface, CVE-2025-27463 3. XenBus, CVE-2025-27464
Severity CVSS v4.0: CRITICAL
Last modification:
09/07/2026

CVE-2025-58146

Publication date:
09/07/2026
There are multiple issues.<br /> <br /> 1. Updates to the XAPI database sanitise input strings, but try<br /> generating the notification using the unsanitised input. This<br /> causes the database&amp;#39;s event thread to terminate and cease further<br /> processing.<br /> <br /> 2. XAPI&amp;#39;s UTF-8 encoder implements v3.0 of the Unicode spec, but XAPI<br /> uses libraries which conform to the stricter v3.1 of the Unicode<br /> spec. This causes some strings to be accepted as valid UTF-8 by<br /> XAPI, but rejected by other libraries in use. Notably, such strings<br /> can be entered into the database, after which the database can no<br /> longer be loaded.<br /> <br /> 3. There is no input sanitisation for Map/Set updates on objects in the<br /> XAPI database.
Severity CVSS v4.0: CRITICAL
Last modification:
09/07/2026

CVE-2025-58151

Publication date:
09/07/2026
varstored is a component of the Xapi toolstack handling UEFI Variables<br /> for a VM. It has a communication path with OVMF inside the VM involving<br /> mapping a buffer prepared by OVMF.<br /> <br /> Within varstored, there were insufficient compiler barriers, creating<br /> TOCTOU issues with data in the shared buffer.<br /> <br /> The exact vulnerable behaviour depends on the code generated by the<br /> compiler. In a build of varstored using default settings, the attacker<br /> can control an index used in a jump table.
Severity CVSS v4.0: CRITICAL
Last modification:
09/07/2026

CVE-2026-60108

Publication date:
09/07/2026
Zeek before 8.0.9 contains an uncontrolled memory consumption vulnerability in the FTP analyzer that allows unauthenticated remote attackers to cause process termination by sending a crafted FTP control session negotiating AUTH GSSAPI followed by a large ADAT control line. Attackers can exploit the NVT_Analyzer component&amp;#39;s lack of a maximum line length check, causing it to continuously double its internal buffer without bounds during base64 decoding of an attacker-controlled ADAT token, resulting in denial of service of the Zeek sensor.
Severity CVSS v4.0: HIGH
Last modification:
14/07/2026

CVE-2026-60109

Publication date:
09/07/2026
Zeek before 8.0.9 contains a null pointer dereference vulnerability in its Kerberos protocol analyzer that allows unauthenticated remote attackers to crash the sensor by sending a crafted KRB_ERROR message with error-code 25 (KDC_ERR_PREAUTH_REQUIRED) containing a PA-DATA element with padata-type 2, 3, 11, or 19. Attackers can exploit a parser and analyzer state mismatch where proc_padata() dereferences an uninitialized pa_data_element field selected by the wrong parsing arm, triggering a crash via a single UDP or TCP packet to port 88 without any credentials or prior authentication.
Severity CVSS v4.0: HIGH
Last modification:
14/07/2026

CVE-2026-5005

Publication date:
09/07/2026
Improper neutralization of input during web page generation (&amp;#39;cross-site scripting&amp;#39;) vulnerability in Twiser Informatics Technology Consulting, Trade and Education Inc. OKRs &amp; Goals allows Stored XSS.<br /> <br /> This issue affects OKRs &amp; Goals: from 28220 before 28398.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-56292

Publication date:
09/07/2026
Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension
Severity CVSS v4.0: CRITICAL
Last modification:
23/07/2026

CVE-2026-54798

Publication date:
09/07/2026
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions
Severity CVSS v4.0: HIGH
Last modification:
09/07/2026