Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-15816

Publication date:
07/08/2026
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.
Severity CVSS v4.0: Pending analysis
Last modification:
07/08/2026

CVE-2026-71558

Publication date:
07/08/2026
Heap type confusion vulnerability in Apache Fory C++ deserialization.<br /> <br /> This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to denial of service or arbitrary code execution.<br /> <br /> <br /> Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications not using Apache Fory C++ polymorphic smart-pointer deserialization are not affected.
Severity CVSS v4.0: Pending analysis
Last modification:
07/08/2026

CVE-2026-71559

Publication date:
07/08/2026
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic.<br /> <br /> This issue affects Apache Fory: from 0.16.0 before 1.5.0.  Users of other language implementations are not affected.<br /> <br /> Users are recommended to upgrade to version 1.5.0, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
07/08/2026

CVE-2026-71560

Publication date:
07/08/2026
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization.<br /> <br /> This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service.<br /> <br /> <br /> Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications that do not use Apache Fory C++ or do not use tagged integer fields are not affected.
Severity CVSS v4.0: Pending analysis
Last modification:
07/08/2026

CVE-2026-54210

Publication date:
07/08/2026
Tobit Laboratories AG TeamDavid&amp;#39;s Webbox application implements various file upload functionalities that are <br /> vulnerable to a buffer overflow condition. By specifying an excessively <br /> long filename in a file upload request, an unauthenticated attacker can <br /> trigger a crash of the server, resulting in a denial of service. <br /> Depending on the stack state or if a stack canary can be disclosed <br /> through another vulnerability, this buffer overflow could potentially be<br /> exploited for remote code execution, leading to full compromise of the <br /> server. This issue affects TeamDavid through Rollout 524.
Severity CVSS v4.0: CRITICAL
Last modification:
07/08/2026

CVE-2026-54211

Publication date:
07/08/2026
Tobit Laboratories AG TeamDavid&amp;#39;s Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a<br /> buffer overflow vulnerability in multiple form data parameters. By <br /> submitting excessively long values in these parameters, an authenticated<br /> attacker can trigger a server crash, resulting in denial of service. <br /> Depending on the stack state or if a stack canary can be disclosed <br /> through another vulnerability, this buffer overflow could potentially be<br /> exploited for remote code execution, leading to full compromise of the <br /> server. This issue affects TeamDavid through Rollout 524.
Severity CVSS v4.0: CRITICAL
Last modification:
07/08/2026

CVE-2026-54212

Publication date:
07/08/2026
Tobit Laboratories AG TeamDavid&amp;#39;s Webbox application implements an API endpoint that is vulnerable to a <br /> buffer overflow condition. By submitting a specially crafted JSON body, <br /> such as one that is at least 8 characters long and begins with a number,<br /> an unauthenticated attacker can cause the server to crash, resulting in<br /> denial of service. Depending on the stack state or if a stack canary <br /> can be disclosed through another vulnerability, this buffer overflow <br /> could potentially lead to remote code execution and full compromise of <br /> the server. This issue affects TeamDavid through Rollout 524.
Severity CVSS v4.0: CRITICAL
Last modification:
07/08/2026

CVE-2026-54213

Publication date:
07/08/2026
Tobit Laboratories AG TeamDavid&amp;#39;s Webbox application exposes a functionality that allows the server to be <br /> shut down when a specific endpoint (/internalRestart) is accessed. This <br /> endpoint is accessible to unauthenticated users over the public <br /> Internet. Instead of “restarting”, the server shuts completely down. As a<br /> result, a remote attacker can trigger a persistent denial of service by<br /> shutting down the web server without requiring authentication. Recovery<br /> requires manual administrator intervention to restart the service. This issue affects TeamDavid through Rollout 524.
Severity CVSS v4.0: CRITICAL
Last modification:
07/08/2026

CVE-2026-54204

Publication date:
07/08/2026
Tobit Laboratories AG TeamDavid&amp;#39;s Webbox &amp;#39;s search functionality accepts a “pathnameroot” <br /> parameter, which can be set to network locations using UNC paths (e.g., <br /> “\\Server\Share”). The server processes these paths without validation, <br /> resulting in outbound connection attempts to attacker-controlled SMB <br /> servers. This enables unauthenticated attackers to trigger the server to<br /> authenticate to arbitrary SMB endpoints, potentially exposing NTLM <br /> authentication information (such as NTLM hashes). If outbound <br /> connections to port 445 (SMB) are permitted, attackers can use this to <br /> conduct SMB relay or credential theft attacks. Exploitation of the <br /> “pathnameroot” parameter is possible without authentication.<br /> <br /> This issue affects TeamDavid through Rollout 524.
Severity CVSS v4.0: HIGH
Last modification:
07/08/2026

CVE-2026-54207

Publication date:
07/08/2026
Tobit Laboratories AG TeamDavid&amp;#39;s Webbox &amp;#39;s move archive functionality (“!ArcEntryMove”) accepts <br /> an arbitrary path, which can be set to network locations using UNC paths<br /> (e.g., “\\Server\Share”). The server processes these paths without <br /> validation, resulting in outbound connection attempts to <br /> attacker-controlled SMB servers. This enables au-thenticated attackers <br /> to trigger the server to authenticate to arbitrary SMB endpoints, <br /> potentially exposing NTLM authentication information (such as NTLM <br /> hashes). If outbound connections to port 445 (SMB) are permitted, <br /> attackers can use this to conduct SMB relay or credential theft attacks.<br /> Exploitation of the “pathname” parameter is possible without <br /> authentication. This issue affects TeamDavid through Rollout 524.
Severity CVSS v4.0: MEDIUM
Last modification:
07/08/2026

CVE-2026-54208

Publication date:
07/08/2026
Tobit Laboratories AG TeamDavid&amp;#39;s Webbox application is vulnerable to arbitrary file write, allowing an <br /> unauthenticated attacker to create or write into existing files on the <br /> server with attacker-controlled content. This is possible because user <br /> input is written directly to files without proper validation or <br /> restriction on file types. As a result, an attacker can create files <br /> (e.g., .htm), containing malicious JavaScript code. When a user accesses<br /> a file created in this way, stored cross-site scripting is triggered. This issue affects TeamDavid through Rollout 524.
Severity CVSS v4.0: HIGH
Last modification:
07/08/2026

CVE-2026-54209

Publication date:
07/08/2026
Tobit Laboratories AG TeamDavid&amp;#39;s Webbox application handles password changes using a function triggered by <br /> including the string "(editini)" in the file path, writing the new <br /> password to the specified "Archive.ini" file. However, the application <br /> does not verify that the provided path actually refers to an <br /> "Archive.ini" file. If an attacker specifies a different file with <br /> excessive size, a buffer overflow occurs. This vulnerability allows an <br /> unauthenticated attacker to crash the server, resulting in denial of <br /> service. This issue affects TeamDavid through Rollout 524.
Severity CVSS v4.0: HIGH
Last modification:
07/08/2026