Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-57436

Publication date:
25/06/2026
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::Document#root= validated only that the new root was a Nokogiri::XML::Node, allowing a DTD node to be set as the document root. The result is a heap use-after-free during garbage collection or finalization, leading to an invalid memory read or potentially a segfault. This vulnerability is fixed in 1.19.4.
Severity CVSS v4.0: LOW
Last modification:
26/06/2026

CVE-2026-57437

Publication date:
25/06/2026
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::XPathContext did not keep its source document alive for garbage collection. If an XPathContext outlived its document and the document was collected, evaluating an XPath expression could read invalid memory and potentially segfault. This is only reachable when application code constructs an XPathContext directly and lets the document become unreachable while continuing to use the context. The normal Document#xpath, #css, and related search methods are not affected, and it is not triggerable by malicious document input. This vulnerability is fixed in 1.19.4.
Severity CVSS v4.0: LOW
Last modification:
26/06/2026

CVE-2026-57235

Publication date:
25/06/2026
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::NodeSet#[] (and its alias #slice) checked the requested index against the node set's bounds using a 32-bit-truncated copy of the index. A large negative index could pass the check and then be used at full width, reading outside the node set's storage. On CRuby this is an out-of-bounds read that typically crashes the process; on JRuby it is not memory-unsafe but returns an incorrect node. This vulnerability is fixed in 1.19.4.
Severity CVSS v4.0: MEDIUM
Last modification:
26/06/2026

CVE-2026-57236

Publication date:
25/06/2026
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, calling Document#encoding= with an invalid encoding (e.g., a non-string, or a string containing a null byte) raises an exception, but only after freeing the document's current encoding string without replacing it. The document is left referencing freed memory, so the next call to Document#encoding reads invalid memory, which can cause a segfault or leak freed bytes into a Ruby String. Affects the CRuby (libxml2) implementation only; JRuby is not affected. This vulnerability is fixed in 1.19.4.
Severity CVSS v4.0: LOW
Last modification:
26/06/2026

CVE-2026-57434

Publication date:
25/06/2026
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri contains a bug when calling certain methods on allocated-but-uninitialized native wrapper classes that inherit from Nokogiri::XML::Node. This caused a NULL pointer dereference that could crash the process. This vulnerability is fixed in 1.19.4.
Severity CVSS v4.0: LOW
Last modification:
26/06/2026

CVE-2026-57234

Publication date:
25/06/2026
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse option, which Nokogiri turns on by default for Nokogiri::XML::Schema (see CVE-2020-26247), was not correctly enforced on the JRuby implementation. As a result, a schema parsed with default options could still cause external resources to be fetched over the network, potentially enabling SSRF or XXE attacks. This vulnerability is fixed in 1.19.4.
Severity CVSS v4.0: Pending analysis
Last modification:
26/06/2026

CVE-2026-49319

Publication date:
25/06/2026
Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0 manufactured by ALPS ALPINE CO., LTD., is vulnerable to a roll-back attack against its rolling-code authentication. <br /> <br /> <br /> <br /> An attacker within RF range who records two consecutive lock or unlock transmissions from a legitimate key fob can later replay the same pair of transmissions repeatedly. During testing, replaying the first captured transmission caused the RKES to enter a state in which replaying the second captured transmission resulted in a successful lock or unlock operation of the vehicle. Tested and confirmed on a 2024 Suzuki Swift (SWIFT ISG GLS AC 1.2 5P 4x2 TM).
Severity CVSS v4.0: MEDIUM
Last modification:
26/06/2026

CVE-2026-56053

Publication date:
25/06/2026
Subscriber PHP Object Injection in EventPrime
Severity CVSS v4.0: Pending analysis
Last modification:
26/06/2026

CVE-2026-56054

Publication date:
25/06/2026
Subscriber Arbitrary File Deletion in JS Help Desk
Severity CVSS v4.0: Pending analysis
Last modification:
25/06/2026

CVE-2026-56051

Publication date:
25/06/2026
Unauthenticated Cross Site Scripting (XSS) in TablePress
Severity CVSS v4.0: Pending analysis
Last modification:
29/06/2026

CVE-2026-56014

Publication date:
25/06/2026
Unauthenticated Cross Site Scripting (XSS) in Master Slider
Severity CVSS v4.0: Pending analysis
Last modification:
26/06/2026

CVE-2026-56006

Publication date:
25/06/2026
Unauthenticated Cross Site Scripting (XSS) in H5P
Severity CVSS v4.0: Pending analysis
Last modification:
25/06/2026