Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-44957

Publication date:
23/06/2026
A missing access control check when invoking various modify methods in the XML‑RPC API of Revive Adserver 6.0.6 and earlier. The API allowed entities to be reassigned to different parent entities, leading to inconsistent ownership relationships. This issue was exploitable only in combination with CVE‑2026‑34917 or with third‑party API extensions that expose API functionality to low‑privileged users. Access control checks have been added to validate access to parent entities in the API modify methods.
Severity CVSS v4.0: Pending analysis
Last modification:
23/06/2026

CVE-2026-42867

Publication date:
23/06/2026
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (POST /api/v1/knowledge_bases). This occurs because user-supplied knowledge base names are used directly to create file paths without proper sanitization or containment checks. An authenticated attacker can exploit this flaw to create directories and write files anywhere on the server's filesystem. This vulnerability is fixed in 1.9.0.
Severity CVSS v4.0: Pending analysis
Last modification:
26/06/2026

CVE-2026-34912

Publication date:
23/06/2026
A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier, or via its API allows a low‑privileged user could link their zones to banners or campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships. Ownership validation has been added to ensure that banners and campaigns can only be linked to zones managed by the same account.
Severity CVSS v4.0: Pending analysis
Last modification:
23/06/2026

CVE-2026-34913

Publication date:
23/06/2026
A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to link their trackers to campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships. Ownership validation has been added to ensure that campaigns can only be linked to trackers owned by the same advertiser.
Severity CVSS v4.0: Pending analysis
Last modification:
23/06/2026

CVE-2026-34914

Publication date:
23/06/2026
A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all parameters processed by the script are properly validated.
Severity CVSS v4.0: Pending analysis
Last modification:
23/06/2026

CVE-2026-34915

Publication date:
23/06/2026
A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all parameters processed by the script are properly validated.
Severity CVSS v4.0: Pending analysis
Last modification:
23/06/2026

CVE-2026-34916

Publication date:
23/06/2026
A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical parameter to inject malicious PHP code into the compiledlimitations field on the database and have it executed during banner delivery. Input sanitisation has been improved to ensure that the parameter is properly validated.
Severity CVSS v4.0: Pending analysis
Last modification:
23/06/2026

CVE-2026-33760

Publication date:
23/06/2026
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monitor router exposes 7 endpoints that perform read, write, and delete operations on user-owned resources — messages, sessions, build artifacts, and LLM transaction logs — without verifying that the authenticated requester owns the targeted resource. Any authenticated user can read, modify, rename, or permanently delete another user's data by supplying the target's resource ID or flow_id. This is a classic IDOR/BOLA vulnerability. Notably, the same source file (monitor.py) contains one correctly-implemented endpoint that uses an ownership check, demonstrating the correct pattern was known but inconsistently applied. This vulnerability is fixed in 1.9.0.
Severity CVSS v4.0: Pending analysis
Last modification:
26/06/2026

CVE-2026-12958

Publication date:
23/06/2026
Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary.<br /> <br /> <br /> <br /> To remediate this issue, users should upgrade to version 1.69.0 or higher.
Severity CVSS v4.0: HIGH
Last modification:
23/06/2026

CVE-2026-12957

Publication date:
23/06/2026
Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the user to trust the workspace when prompted.<br /> <br /> <br /> <br /> To remediate this issue, users should upgrade to Language Servers for AWS version 1.65.0 or higher.
Severity CVSS v4.0: HIGH
Last modification:
23/06/2026

CVE-2026-11940

Publication date:
23/06/2026
tarfile.extractall() with the &amp;#39;data&amp;#39; or &amp;#39;tar&amp;#39;<br /> filter could be bypassed by a crafted archive where a hardlink <br /> references a symlink stored at a deeper name than the hardlink itself.  <br /> The extraction fallback validated the symlink at it&amp;#39;s archived location <br /> but recreated it at the hardlink&amp;#39;s shallower<br /> path, letting a relative<br /> target the filter judged contained escape the destination directory.  <br /> This allowed a malicious tar archive to create a symlink pointing <br /> outside the destination, enabling out-of-destination file reads or <br /> writes. This was an incomplete fix of CVE-2025-4330.
Severity CVSS v4.0: HIGH
Last modification:
06/08/2026

CVE-2025-61022

Publication date:
23/06/2026
An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
Severity CVSS v4.0: Pending analysis
Last modification:
23/06/2026