Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-48954

Publication date:
07/07/2026
Improper validation leads to a generic XSS vector in the language override feature.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-55435

Publication date:
07/07/2026
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridgedserver`, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended user's unexpired token keeps working. Practical impact is limited to already-issued API keys of suspended users until those keys are deleted. Versions 2.32.7, 2.33.8, and 2.34.2 patch the issue. As a workaround, on suspension, delete the user's API keys via `DELETE /api/v2/users/{user}/keys`.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-48958

Publication date:
07/07/2026
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-48957

Publication date:
07/07/2026
An improper access check allows unauthorized users to access com_privacy datasets.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-48956

Publication date:
07/07/2026
An improper access check allows users to display a list of modules in the frontend.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-48955

Publication date:
07/07/2026
An improper access check allows unauthorized users to access workflow stage and transition information.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-48953

Publication date:
07/07/2026
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-48952

Publication date:
07/07/2026
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-48951

Publication date:
07/07/2026
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-48950

Publication date:
07/07/2026
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-48949

Publication date:
07/07/2026
Lack of validation leads to an XSS vulnerability in the MFA management views.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-48948

Publication date:
07/07/2026
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026