Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-82364

Publication date:
29/08/2026
A security vulnerability has been detected in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /order/submit of the component Order Submission. The manipulation leads to race condition. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The vendor deleted the GitHub issue for this vulnerability without and explanation.
Severity CVSS v4.0: LOW
Last modification:
29/08/2026

CVE-2026-80725

Publication date:
29/08/2026
In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net: gro: properly validate BIG TCP aggregation criteria<br /> <br /> When GRO attempts to aggregate packets beyond GRO_LEGACY_MAX_SIZE (64KB),<br /> BIG TCP should only be permitted for plain IPv4 TCP and plain IPv6 TCP<br /> (with sufficient MAC header room to insert the temporary HBH jumbo header).<br /> <br /> However, commit b1a78b9b9886 ("net: add support for ipv4 big tcp")<br /> loosened the check in skb_gro_receive(), leading to several issues:<br /> <br /> 1. skb_gro_receive() checked skb_headroom(p) instead of the actual space<br /> before the MAC header (p-&gt;mac_header). Because skb_headroom(p) includes<br /> mac_len, crafted frames (e.g. injected via AF_PACKET) can pass the check<br /> with p-&gt;mac_header head,<br /> causing an out-of-bounds write and wrapping skb-&gt;mac_header.<br /> 2. It allowed non-IP protocols such as software VLAN (ETH_P_8021Q /<br /> ETH_P_8021AD) to aggregate beyond 64KB because<br /> p-&gt;protocol != ETH_P_IPV6 was true.<br /> 3. It checked p-&gt;encapsulation instead of NAPI_GRO_CB(skb)-&gt;encap_mark,<br /> allowing encapsulated flows (e.g. SIT / IPv6-in-IPv4) to aggregate<br /> beyond 64KB.<br /> <br /> Fix skb_gro_receive() to strictly enforce:<br /> - NAPI_GRO_CB(skb)-&gt;proto == IPPROTO_TCP<br /> - Not encapsulated (!NAPI_GRO_CB(skb)-&gt;encap_mark &amp;&amp; !p-&gt;encapsulation)<br /> - Protocol must be either ETH_P_IP or ETH_P_IPV6<br /> - If ETH_P_IPV6, p-&gt;mac_header must be at least<br /> sizeof(struct hop_jumbo_hdr)<br /> <br /> Returning -E2BIG from skb_gro_receive() ensures that packets which cannot<br /> become BIG TCP are cleanly flushed at
Severity CVSS v4.0: Pending analysis
Last modification:
29/08/2026

CVE-2026-81346

Publication date:
29/08/2026
The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans.
Severity CVSS v4.0: Pending analysis
Last modification:
29/08/2026

CVE-2026-81200

Publication date:
29/08/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users&amp;#39; order billing details, including name, email address, phone number and postal address, by enumerating order IDs.
Severity CVSS v4.0: Pending analysis
Last modification:
29/08/2026

CVE-2026-81342

Publication date:
29/08/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user registration before using it, allowing unauthenticated attackers to redirect users to arbitrary external URLs.
Severity CVSS v4.0: Pending analysis
Last modification:
29/08/2026

CVE-2026-81026

Publication date:
29/08/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the corresponding order completed, allowing unauthenticated users to complete full-price orders and gain access to paid content by paying only a token amount.
Severity CVSS v4.0: Pending analysis
Last modification:
29/08/2026

CVE-2026-80311

Publication date:
29/08/2026
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before cancelling it, allowing a user with a confirmed portal session to cancel subscriptions belonging to other customers.<br /> <br /> Exploitation requires the attacker to know the target subscription&amp;#39;s identifier, which is high-entropy and not enumerable through the Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5.
Severity CVSS v4.0: Pending analysis
Last modification:
29/08/2026

CVE-2026-80488

Publication date:
29/08/2026
The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks.
Severity CVSS v4.0: Pending analysis
Last modification:
29/08/2026

CVE-2026-77012

Publication date:
29/08/2026
The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or destination paths it is given, allowing unauthenticated attackers to read arbitrary files from the server, force it to issue arbitrary requests and retrieve the responses, and write attacker-supplied content outside the uploads directory.
Severity CVSS v4.0: Pending analysis
Last modification:
29/08/2026

CVE-2026-77704

Publication date:
29/08/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment&amp;#39;s status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were left awaiting approval and overwriting another customer&amp;#39;s booking status on a shared appointment.
Severity CVSS v4.0: Pending analysis
Last modification:
29/08/2026

CVE-2026-77786

Publication date:
29/08/2026
The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself requires for the settings being changed, allowing users with the Editor role to modify site-wide core WordPress settings that are reserved to administrators.
Severity CVSS v4.0: Pending analysis
Last modification:
29/08/2026

CVE-2026-77010

Publication date:
29/08/2026
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authorisation checks on its REST API routes and does not consistently enforce the per-class access code, allowing unauthenticated users to obtain a signed meeting join link for any classroom, including one protected by an access code, and to join it with moderator privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
29/08/2026