Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-77806

Publication date:
21/08/2026
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.
Severity CVSS v4.0: Pending analysis
Last modification:
21/08/2026

CVE-2026-75946

Publication date:
21/08/2026
A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior to 1101.2608.0.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
Severity CVSS v4.0: HIGH
Last modification:
21/08/2026

CVE-2026-15580

Publication date:
21/08/2026
vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse.<br /> <br /> This issue affects the PassPortal browser extension: before 3.49.6.
Severity CVSS v4.0: MEDIUM
Last modification:
21/08/2026

CVE-2026-76613

Publication date:
21/08/2026
Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection allowed any contributor-level user to inject own content into SQL queries.
Severity CVSS v4.0: CRITICAL
Last modification:
21/08/2026

CVE-2026-77028

Publication date:
21/08/2026
Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo
Severity CVSS v4.0: MEDIUM
Last modification:
21/08/2026

CVE-2026-77780

Publication date:
21/08/2026
Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus<br /> Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with transaction and accounting<br /> creation permissions to disclose another company&amp;#39;s bank account name, bank name and card<br /> last four digits via a bank_account_id or bank_card_id belonging to that company in POST<br /> /transaction/save, which is persisted and rendered without any company ownership check.
Severity CVSS v4.0: MEDIUM
Last modification:
21/08/2026

CVE-2026-75115

Publication date:
21/08/2026
Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 - The Filesystem source&amp;#39;s path filter is vulnerable to glob-based pattern attacks, allowing authorized users to read arbitrary files.
Severity CVSS v4.0: HIGH
Last modification:
21/08/2026

CVE-2026-76611

Publication date:
21/08/2026
Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo
Severity CVSS v4.0: MEDIUM
Last modification:
21/08/2026

CVE-2026-76612

Publication date:
21/08/2026
Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo
Severity CVSS v4.0: HIGH
Last modification:
21/08/2026

CVE-2026-59654

Publication date:
21/08/2026
Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack&amp;#39;s scoped global configuration functionality. It affects different modules and plugins of the CloudStack management server, including Quota, Host-HA, etc., and may lead to eventual denial of service (DoS) scenario for the management server.<br /> <br /> This issue affects Apache CloudStack: from 4.7.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.<br /> <br /> Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Severity CVSS v4.0: MEDIUM
Last modification:
21/08/2026

CVE-2026-77759

Publication date:
21/08/2026
Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero<br /> Flow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions of other<br /> companies on the same instance via an incremented identifier in GET /api/transaction/{id},<br /> which is resolved without company scoping and without any permission check.
Severity CVSS v4.0: HIGH
Last modification:
21/08/2026

CVE-2026-77775

Publication date:
21/08/2026
Headroom&amp;#39;s LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header value, requires only that it parse with an http or https scheme and a hostname, and returns it for use as the upstream base; _select_passthrough_base_url in headroom/providers/proxy_routes.py reads the same header for the passthrough routes. No check rejects loopback, link-local, or RFC 1918 destinations, and because the component is a proxy the upstream response is returned to the caller, so the request reaches internal services and cloud metadata addresses and their responses are disclosed. The Authorization header accompanying the request is forwarded unchanged to the caller-designated host. The pip console script binds 127.0.0.1 by default, but the reference docker-compose.yml ships --host 0.0.0.0 with published ports and no required HEADROOM_PROXY_TOKEN, which the server itself warns about at startup, so a deployment following the shipped compose exposes the affected data-plane routes to the network without authentication.
Severity CVSS v4.0: HIGH
Last modification:
21/08/2026