Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-62323

Publication date:
31/07/2026
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the session-id prefix of a WOPI access token and does not enforce the requested viewer action, allowing a malicious or compromised WOPI viewer with a view session to forge the token suffix and invoke WOPI write routes for the underlying file. This issue is fixed in version 4.17.0.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-63220

Publication date:
31/07/2026
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an attacker could spoof these headers and cause the application to incorrectly treat an HTTP request as secure. This may have impacted applications that rely on isSecure(), force_https(), forceGlobalSecureRequests, or similar logic to enforce HTTPS-only access or make security-sensitive decisions. Exploitability depends on deployment configuration. Applications are most exposed if the backend is reachable directly over HTTP, or if a reverse proxy/load balancer forwards client-supplied forwarding headers without stripping or overwriting them. This issue has been fixed in version 4.7.4.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-55497

Publication date:
31/07/2026
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed file size but do not limit decoded pixel dimensions, allowing an authenticated user to submit a small PNG, JPEG, or GIF that triggers an unbounded allocation and terminates the Cloudreve process through fatal out-of-memory behavior. This issue is fixed in version 4.17.0.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-55499

Publication date:
31/07/2026
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscription resolves the share root to the owner’s parent folder and subscribes to that folder topic, allowing an authenticated share recipient to receive names, paths, rename targets, event types, and hashed identifiers for unshared sibling files and folders. This issue is fixed in version 4.17.0.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-55502

Publication date:
31/07/2026
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetOauthRedirectService persists caller-supplied OneDrive secret and app_id values, allowing an OAuth token without Admin.Write to modify storage policy credentials. The route is inside the admin group that requires Admin.Read, but it does not add the local Admin.Write guard used by sibling policy mutation routes. Its handler persists attacker-supplied secret and app_id values into the selected OneDrive storage policy before returning an OAuth URL. This issue is fixed in version 4.17.0.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-43832

Publication date:
31/07/2026
Successful exploitation of the<br /> vulnerability could allow an unauthenticated attacker to exploit a stack-based<br /> buffer overflow in the Cookie parsing methods to conduct code execution when<br /> the SafeEnhancement feature is enabled.
Severity CVSS v4.0: CRITICAL
Last modification:
31/07/2026

CVE-2026-43833

Publication date:
31/07/2026
Successful exploitation of the vulnerability<br /> could allow an authenticated attacker to exploit a stack-based buffer overflow<br /> in the upload functionality to conduct code execution.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-55495

Publication date:
31/07/2026
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than a filename, allowing slash and dot-dot segments to escape the source file directory and create or conditionally overwrite files elsewhere in the same owner account. This issue is fixed in version 4.17.0.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-55496

Publication date:
31/07/2026
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActive without adding a StatusActive predicate and serializes matches at RedactLevelUser, allowing any logged-in user to enumerate email addresses and profile metadata for inactive or banned accounts. The service calls userClient.SearchActive, but despite its name that method filters only by email/nickname keyword and never adds a StatusActive predicate — while the sibling lookups GetActiveByID and GetActiveByDavAccount, defined a few lines above it, do. Search hits are serialized at RedactLevelUser, which includes the email address. This issue is fixed in version 4.17.0.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-43830

Publication date:
31/07/2026
Successful exploitation of the<br /> command injection vulnerability could allow an attacker to execute arbitrary<br /> commands during the firmware upgrade file verification process.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-43831

Publication date:
31/07/2026
Successful<br /> exploitation of the vulnerability could allow an unauthenticated attacker to<br /> exploit a stack-based buffer overflow in the log message functionality to<br /> conduct code execution.
Severity CVSS v4.0: CRITICAL
Last modification:
31/07/2026

CVE-2026-43829

Publication date:
31/07/2026
Successful<br /> exploitation of the vulnerability could allow an unauthenticated attacker to<br /> exploit a stack-based buffer overflow in the password functionality to conduct<br /> code execution when the SafeEnhancement feature is enabled.
Severity CVSS v4.0: CRITICAL
Last modification:
31/07/2026