Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-81625

Publication date:
27/08/2026
A remote attacker with user privileges may use a malicious or compromised NASL vulnerability test (VT) on the affected products to trigger a stack buffer overflow and gain full access on the compromised system.
Severity CVSS v4.0: HIGH
Last modification:
27/08/2026

CVE-2026-81574

Publication date:
27/08/2026
In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format<br /> specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory<br /> and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and<br /> remotely when combined with CVE-2026-81573 by setting General.ProxyServer and then triggering this<br /> vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-81575

Publication date:
27/08/2026
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and<br /> the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, causing a<br /> segmentation fault that ultimately crashes the CodeMeter Runtime.
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-81576

Publication date:
27/08/2026
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak<br /> SID as sole authenticator. An attacker can brute-force the SID, recover another session&amp;#39;s handle number, and read<br /> license information belonging to another handle.
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-81579

Publication date:
27/08/2026
In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be leveraged to execute arbitrary code, run an administrator shell, or gain full control over the system.
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-81581

Publication date:
27/08/2026
Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside the scope of the program. This usually results in a denial of service, yet we cannot rule out the possibility of exploits that can cause Remote Code Execution and Privilege Escalation (since the driver runs with system privileges).
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-81272

Publication date:
27/08/2026
Editor Broken Access Control in FluentPlayer Pro
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-81273

Publication date:
27/08/2026
Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-81274

Publication date:
27/08/2026
Subscriber Broken Access Control in Ditty
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-81276

Publication date:
27/08/2026
Unauthenticated Broken Access Control in Kali Forms
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-81277

Publication date:
27/08/2026
Contributor SQL Injection in Suggestion Engine for WooCommerce
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-81279

Publication date:
27/08/2026
Subscriber Broken Access Control in Push Notification for Post and BuddyPress
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026