Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-47831

Publication date:
09/07/2026
Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-builder allows a remote attacker to brute-force the resulting SSH login via TCP/22.<br /> Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.
Severity CVSS v4.0: HIGH
Last modification:
09/07/2026

CVE-2026-47840

Publication date:
09/07/2026
A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during simple-bind authentication, and return forged group memberships that grant themselves admin scopes. This affects every deployment that authenticates users against LDAP over StartTLS.<br /> Affected versions: UAA versions prior to v78.13.0; Cf-deployment versions prior to v56.2.0.
Severity CVSS v4.0: CRITICAL
Last modification:
09/07/2026

CVE-2026-47829

Publication date:
09/07/2026
Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator&amp;#39;s workstation.<br /> Affected versions: bosh-cli versions prior to v7.10.4.
Severity CVSS v4.0: HIGH
Last modification:
13/07/2026

CVE-2026-11875

Publication date:
09/07/2026
The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session cookie, allowing unauthenticated attackers to forge it and impersonate any ticket owner (identified by email address) to read, reply to, and close that person&amp;#39;s support tickets.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-12270

Publication date:
09/07/2026
The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belonging to its onboarding assistant: the capability check is only applied when an attacker-controllable request header holds a specific value, so it can be bypassed by omitting or changing that header. This makes it possible for unauthenticated attackers to read onboarding status information, modify the related Everest Forms WordPress plugin before 3.5.0 options, and trigger an email from the site to an arbitrary address.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-12516

Publication date:
09/07/2026
The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated media-proxying endpoint, allowing anonymous users to make the site fetch arbitrary URLs, including internal and private-network addresses, and read back the response body. This results in a full-read Server-Side Request Forgery and open proxy.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-12517

Publication date:
09/07/2026
The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated site-info endpoint before fetching it, allowing anonymous users (the gating nonce is exposed on public pages carrying an embed) to make the site request internal and private-network URLs and read back the parsed page metadata. This is a Server-Side Request Forgery.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-47828

Publication date:
09/07/2026
During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM&amp;#39;s DAV blobstore over HTTPS without verifying the server certificate, even though a CA certificate for that endpoint is available in the installation manifest. A network attacker can terminate the TLS connection, harvest the Basic-auth credentials, and read the rendered-templates archive containing every bootstrap secret for the new BOSH Director, then replay the credentials against the real VM&amp;#39;s agent for root code execution.<br /> Affected versions: bosh-cli versions prior to v7.10.4.
Severity CVSS v4.0: HIGH
Last modification:
13/07/2026

CVE-2026-47826

Publication date:
09/07/2026
The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information.<br /> Affected versions: BOSH CLI tool versions prior to v7.10.4.
Severity CVSS v4.0: HIGH
Last modification:
13/07/2026

CVE-2026-11571

Publication date:
09/07/2026
The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other users&amp;#39; form submission records via predictable, enumerable filenames.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-11869

Publication date:
09/07/2026
The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-processing path of its data subject access request feature, allowing unauthenticated attackers to generate and download the full personal-data export (including name, postal address, phone number, email, and comment content) of any user, customer, or commenter by supplying their email address.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-5523

Publication date:
09/07/2026
The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.8. This is due to the update_user() function accepting a user ID parameter from form submissions without verifying that the authenticated user has permission to edit that specific user account, and the handle_register_submission() function only checking if any user is logged in rather than validating permissions for the target user. This makes it possible for authenticated attackers, with subscriber-level access and above, to change the email address and password of any user account, including administrators, resulting in complete account takeover.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026