Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-44089

Publication date:
23/06/2026
Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. This vulnerability could be exploited to cause the program to crash and to execute code remotely. This allows the attacker to perform actions as root including reading and editing data, as well as bricking the router.<br /> <br /> Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 9.3.5u.6146_B20201023 but may also affect other versions.
Severity CVSS v4.0: CRITICAL
Last modification:
23/06/2026

CVE-2026-10711

Publication date:
23/06/2026
Missing authentication for critical function vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. CafePlus allows Accessing Functionality Not Properly Constrained by ACLs.<br /> <br /> This issue affects CafePlus: from 12.05.03 before 12.05.04.
Severity CVSS v4.0: Pending analysis
Last modification:
23/06/2026

CVE-2026-10857

Publication date:
23/06/2026
Improper neutralization of input during web page generation (&amp;#39;cross-site scripting&amp;#39;) vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. E-Commerce allows Reflected XSS.<br /> <br /> This issue affects e-Commerce: before 1.25.01.06.
Severity CVSS v4.0: Pending analysis
Last modification:
23/06/2026

CVE-2025-71376

Publication date:
23/06/2026
picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.autocomplete.AutoComplete.fetch_completions in reduce methods. Attackers can embed undetected code in pickle files that executes arbitrary commands when loaded by victims.
Severity CVSS v4.0: HIGH
Last modification:
23/06/2026

CVE-2025-71370

Publication date:
23/06/2026
picklescan before 0.0.28 fails to detect malicious torch.jit.unsupported_tensor_ops.execWrapper function calls embedded in pickle files. Attackers can craft malicious pickle files that bypass picklescan detection and execute arbitrary code when loaded via pickle.load().
Severity CVSS v4.0: HIGH
Last modification:
23/06/2026

CVE-2025-71341

Publication date:
23/06/2026
picklescan before 0.0.29 fails to detect the profile.Profile.runctx function when analyzing pickle files, allowing attackers to embed undetected malicious code. Remote attackers can craft malicious pickle files using profile.Profile.runctx in the reduce method to achieve remote code execution when the pickle file is loaded.
Severity CVSS v4.0: HIGH
Last modification:
23/06/2026

CVE-2025-71365

Publication date:
23/06/2026
picklescan before 0.0.33 fails to detect malicious pickle files that invoke numpy.f2py.crackfortran.myeval function through the reduce method. Attackers can craft malicious pickle files embedding arbitrary code that evades picklescan detection and executes remote code when loaded.
Severity CVSS v4.0: HIGH
Last modification:
23/06/2026

CVE-2023-54365

Publication date:
23/06/2026
Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library&amp;#39;s HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the &amp;#39;Rapid Reset&amp;#39; technique). A remote attacker can rapidly create and cancel HTTP/2 streams to exhaust server resources and cause service unavailability.
Severity CVSS v4.0: HIGH
Last modification:
15/07/2026

CVE-2026-4983

Publication date:
23/06/2026
Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content-Type: image/svg+xml without security headers such as Content-Security-Policy or Content-Disposition: attachment. This allows an attacker to publish an extension with a malicious SVG icon and achieve stored cross-site scripting (XSS) when a user navigates directly to the icon URL.<br /> <br /> <br /> <br /> <br /> On deployments using local storage, script execution occurs within the Open VSX application origin, enabling session hijacking, authentication token theft, and unauthorized extension publishing. On deployments backed by external storage (such as open-vsx.org with an S3-backed CDN), execution is confined to the storage origin, reducing impact but still permitting phishing attacks and credential harvesting through attacker-crafted pages.
Severity CVSS v4.0: Pending analysis
Last modification:
24/06/2026

CVE-2026-11374

Publication date:
23/06/2026
In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted<br /> by an unauthenticated user, leading to account takeover.
Severity CVSS v4.0: Pending analysis
Last modification:
24/06/2026

CVE-2026-9733

Publication date:
23/06/2026
Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter.<br /> <br /> When no state generator is specified in the constructor, the module defaults to using a SHA-1 hash of predictable and low-entropy sources, including the epoch time (which is leaked via the HTTP Date header) and a call to Perl&amp;#39;s built-in rand function.<br /> <br /> A predictable state allows an attacker to hijack another user&amp;#39;s session through cross site request forgery (CSRF).
Severity CVSS v4.0: Pending analysis
Last modification:
23/06/2026

CVE-2026-10521

Publication date:
23/06/2026
An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters. This can result in a total loss of confidentiality, integrity and availability.
Severity CVSS v4.0: HIGH
Last modification:
23/06/2026