Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-59692

Publication date:
09/07/2026
A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
19/08/2026

CVE-2026-56288

Publication date:
09/07/2026
GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) data structures, causing the application to pass a NULL pointer to fwrite() during patch processing.<br /> An attacker can trigger this condition with a malicious patch file, causing the utility to crash and resulting in a denial of service.<br /> <br /> <br /> <br /> This issue has been fixed in the commit e6d6a4e021660679d7fc9150f981d4920f722313
Severity CVSS v4.0: MEDIUM
Last modification:
13/07/2026

CVE-2026-56289

Publication date:
09/07/2026
GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position.<br /> This results in excessive CPU consumption and prevents the process from completing.<br /> An attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination.<br /> <br /> <br /> <br /> This issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9
Severity CVSS v4.0: MEDIUM
Last modification:
13/07/2026

CVE-2026-56291

Publication date:
09/07/2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension
Severity CVSS v4.0: CRITICAL
Last modification:
24/07/2026

CVE-2026-4298

Publication date:
09/07/2026
The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. This is due to the dsgvo_reset_policy_service_func() function lacking both capability checks and nonce verification while processing user-supplied parameters to reset plugin options. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset all customized privacy policy content including cookie notices, Google Analytics policies, Facebook policies, and YouTube policies to their default values.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-4275

Publication date:
09/07/2026
The Divi Torque Lite – Divi Theme, Divi Builder &amp; Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. This is due to the use of &amp;#39;__return_true&amp;#39; as the permission_callback for the /install_plugin and /activate_plugin REST API endpoints, which bypasses WordPress&amp;#39;s built-in REST API nonce verification. Although the endpoint callbacks contain internal current_user_can() checks, the absence of nonce verification means that a forged cross-site request from a logged-in administrator&amp;#39;s browser will pass the capability check via the admin&amp;#39;s session cookies. This makes it possible for unauthenticated attackers to install arbitrary plugins from WordPress.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-50644

Publication date:
09/07/2026
SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all rights can inject SQL commands into the audit configuration form which is then saved. The execution is triggered when the audit functionality is accessed (by the attacker or another user).<br /> <br /> This issue was fixed in version 1.56.01.
Severity CVSS v4.0: HIGH
Last modification:
09/07/2026

CVE-2026-12428

Publication date:
09/07/2026
The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_values() function in the /wp-json/acf-field-blocks/v1/values REST endpoint in versions up to, and including, 1.6.2. The permission_callback only verifies the generic publish_posts capability and the handler passes a user-supplied id parameter directly to get_field_objects() without verifying that the requesting user is authorized to read the target object. This makes it possible for authenticated attackers, with Author-level access and above, to read ACF field values from arbitrary posts (including private posts, drafts, posts by other users, and other ACF-supported objects) that they should not have access to.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-13441

Publication date:
09/07/2026
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the &amp;#39;new_event_type_background_color&amp;#39; parameter in all versions up to, and including, 4.3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the plugin&amp;#39;s Guest Submissions setting (allow_submission_by_anonymous_user) to be enabled, which allows unauthenticated attackers to submit event types via the frontend form; when that setting is disabled, exploitation requires at minimum a subscriber-level authenticated account.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-14372

Publication date:
09/07/2026
The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator &amp; Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteFiles function in all versions up to, and including, 3.1.1 This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config).
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-12590

Publication date:
09/07/2026
Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-parser 1.20.6 and 2.3.0. After the fix, invalid limit values throw a clear error at parser construction time instead of silently disabling enforcement, while null and undefined continue to fall back to the default limit of 100kb. Workarounds: Validate the limit value before passing it to body-parser. For example, parse the value at startup and reject any configuration where the result is null or a non-finite number.
Severity CVSS v4.0: Pending analysis
Last modification:
10/07/2026

CVE-2026-5793

Publication date:
09/07/2026
Improper neutralization of input during web page generation (&amp;#39;cross-site scripting&amp;#39;) vulnerability in Inrove Software and Internet Services BiEticaret allows Reflected XSS.<br /> <br /> This issue affects BiEticaret: before v3.3.57.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026