Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-82823

Publication date:
31/08/2026
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-82814. Reason: This candidate is a reservation duplicate of CVE-2026-82814. Notes: All CVE users should reference CVE-2026-82814 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
Severity CVSS v4.0: Pending analysis
Last modification:
31/08/2026

CVE-2026-82802

Publication date:
31/08/2026
A flaw has been found in NASA earthdata-search 1.0.0. Affected by this issue is the function OpenSearchGranuleSearchLambda of the file serverless/src/openSearchGranuleSearch/handler.js of the component granules Endpoint. Executing a manipulation of the argument openSearchOsdd can lead to server-side request forgery. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity CVSS v4.0: MEDIUM
Last modification:
31/08/2026

CVE-2026-75132

Publication date:
31/08/2026
WAPT Server versions 2.6.1.17834 and earlier contains a SQL injection vulnerability in the `columns` parameter of the GET `/api/v3/hosts` endpoint. A remote authenticated user with read-only privileges can inject arbitrary PostgreSQL expressions into the SQL query constructed by WAPT. By exploiting the injection point, an attacker can inject additional PostgreSQL statements, bypass the host scope restrictions applied to the account, and read information from other rows or tables within the database.
Severity CVSS v4.0: HIGH
Last modification:
31/08/2026

CVE-2026-21827

Publication date:
31/08/2026
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data they are not entitled to, caused by improper handling of request data.
Severity CVSS v4.0: Pending analysis
Last modification:
31/08/2026

CVE-2026-78422

Publication date:
31/08/2026
Subject::new_for_owner() in the zbus_polkit crate encodes the uid entry of a unix-process polkit subject as an unsigned 32-bit integer (D-Bus type u), whereas the org.freedesktop.PolicyKit1.Authority interface specifies a signed 32-bit integer (D-Bus type i). Because of this type mismatch, polkit silently discards the caller-supplied UID and instead determines the subject&amp;#39;s owner itself by looking up the PID in /proc, a lookup that is inherently subject to a time-of-check/time-of-use race.<br /> <br /> Consequently, an application that passes a UID obtained from a trustworthy source — for example SO_PEERCRED Unix socket peer credentials — in order to defend against PID reuse receives no protection, and the supplied UID has no effect on the authorization decision. A local unprivileged attacker who can cause an authorized process to terminate and then win the race to have their own process assigned the same PID can be authorized under the identity of the terminated process, bypassing the polkit authorization check and performing actions the attacker is not entitled to.<br /> <br /> This issue affects zbus_polkit before 5.1.0.
Severity CVSS v4.0: HIGH
Last modification:
31/08/2026

CVE-2026-66047

Publication date:
31/08/2026
ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the ppress_connect_process AJAX handler. Attackers can supply a caller-controlled URL through the file request parameter to trigger silent plugin installation and activation, achieving PHP code execution as the web-server user.
Severity CVSS v4.0: CRITICAL
Last modification:
31/08/2026

CVE-2026-63083

Publication date:
31/08/2026
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Severity CVSS v4.0: Pending analysis
Last modification:
31/08/2026

CVE-2026-59111

Publication date:
31/08/2026
Improper neutralization of special elements used in an OS command (&amp;#39;OS command injection&amp;#39;) vulnerability in Digitální a informační agentura (DIA) eObčanka-Identifikace on MacOS enables an attacker to register a custom URL scheme (czeeopauth://) for parameterized application execution. Prior to version 3.6.0, incoming URL parameters were passed to the compiled AppleScript wrapper using concatenation without sufficient sanitization.
Severity CVSS v4.0: Pending analysis
Last modification:
31/08/2026

CVE-2026-19702

Publication date:
31/08/2026
Improper neutralization of special elements used in an OS command (&amp;#39;OS command injection&amp;#39;) vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection.<br /> <br /> This issue affects Pardus Boot Repair: from 1.0.7 before 1.0.8.
Severity CVSS v4.0: Pending analysis
Last modification:
31/08/2026

CVE-2026-19616

Publication date:
31/08/2026
Missing Authorization vulnerability in TBC Technology Inc. KitLogistic allows Accessing Functionality Not Properly Constrained by ACLs.<br /> <br /> This issue affects KitLogistic: before v2.2.2.
Severity CVSS v4.0: Pending analysis
Last modification:
31/08/2026

CVE-2026-74010

Publication date:
31/08/2026
Missing Authorization vulnerability in John James Jacoby bbPress allows Exploiting Incorrectly Configured Access Control Security Levels.<br /> <br /> This issue affects bbPress: from n/a through 2.6.14.
Severity CVSS v4.0: Pending analysis
Last modification:
31/08/2026

CVE-2026-5956

Publication date:
31/08/2026
Improper neutralization of special elements used in an SQL command (&amp;#39;SQL injection&amp;#39;) vulnerability in Ankara Hosting Site Management Panel allows SQL Injection.<br /> <br /> This issue affects Site Management Panel: through 15062026.
Severity CVSS v4.0: Pending analysis
Last modification:
31/08/2026