Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-33801

Publication date:
09/07/2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker sending a specific BGP update over an established BGP session to cause a Denial-of-Service (DoS).<br /> <br /> Upon receipt of a specifically malformed non-inet/inet6 unicast BGP update, an RPD crash and restart is triggered, which will cause a complete service outage until routing has reconverged. The rpd crash occurs before the update can be readvertised, so there is no downstream propagation.<br /> <br /> <br /> This issue affects:<br /> <br /> <br /> <br /> * Junos OS versions 25.2 before 25.2R2;<br /> <br /> <br /> * Junos OS Evolved versions 25.2 before 25.2R2-EVO.<br /> <br /> <br /> <br /> <br /> This issue doesn&amp;#39;t affect Junos OS versions before 25.2R1 nor Junos OS Evolved versions before 25.2R1-EVO.
Severity CVSS v4.0: HIGH
Last modification:
13/07/2026

CVE-2026-31267

Publication date:
09/07/2026
Mercusys MW302R MW302R(EU)_V1_1.4.10 Build 231023 is vulnerable to Buffer Overflow in the administrative web interface. A stack buffer overflow vulnerability in the administrative web interface allows an authenticated attacker with administrative privileges to trigger a system crash by sending a specially crafted request. The vulnerability results in denial of service through control flow manipulation to an arbitrary instruction address.
Severity CVSS v4.0: Pending analysis
Last modification:
10/07/2026

CVE-2025-45422

Publication date:
09/07/2026
Incorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and make arbitrary changes to port forwarding rules.
Severity CVSS v4.0: Pending analysis
Last modification:
10/07/2026

CVE-2026-21901

Publication date:
09/07/2026
A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting or deactivating a specific SSH configuration parameter to create a Denial of Service (DoS).<br /> <br /> A local high-privileged user configuring or deactivating a specific &amp;#39;system services ssh&amp;#39; configuration parameter can exploit a null pointer dereference in one of the functions used by SSH. The function attempts to dereference a null pointer when accessing certain configuration data, resulting in an mgd process crash and restart. Continued execution of these configuration commands will create a sustained Denial of Service (DoS) condition.<br /> <br /> This issue affects:<br /> Junos OS:<br /> <br /> <br /> * from 22.3 before 22.3R3-S5;<br /> * from 22.4 before 22.4R3-S10;<br /> * from 23.2 before 23.2R2-S7;<br /> * from 23.4 before 23.4R2-S8.<br /> <br /> <br /> <br /> <br /> This issue does not affect Junos OS before 22.3R1.<br /> <br /> <br /> <br /> Junos OS Evolved:<br /> * from 22.3R1-EVO before 23.2R2-S7-EVO;<br /> * from 23.4 before 23.4R2-S8-EVO.<br /> <br /> <br /> This issue does not affect Junos OS Evolved before 22.3R1-EVO.
Severity CVSS v4.0: MEDIUM
Last modification:
10/07/2026

CVE-2026-33799

Publication date:
09/07/2026
An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory leak. Over time, continuous receipt of these queries will result in snmpd process memory exhaustion, resulting in a process crash and restart, impacting the ability to monitor the system via SNMP.<br /> <br /> Memory usage can be monitored using the following command:<br /> <br /> user@device&gt; show system processes extensive | match snmpd<br /> <br /> <br /> <br /> <br /> This issue affects:<br /> <br /> Junos OS:<br /> <br /> <br /> * all versions before 21.2R3-S8;<br /> * from 21.4 before 21.4R3-S7;<br /> * from 22.1 before 22.1R3-S6;<br /> * from 22.2 before 22.2R3-S4;<br /> * from 22.3 before 22.3R3-S3;<br /> * from 22.4 before 22.4R3-S2;<br /> * from 23.2 before 23.2R2;<br /> * from 23.4 before 23.4R2.<br /> <br /> <br /> <br /> Junos OS Evolved:<br /> * all versions before 21.2R3-S8-EVO;<br /> * from 21.4 before 21.4R3-S7-EVO;<br /> * all versions of 22.1-EVO,<br /> * from 22.2 before 22.2R3-S4-EVO;<br /> * from 22.3 before 22.3R3-S3-EVO;<br /> * all versions of 22.4-EVO,<br /> * from 23.2 before 23.2R2-EVO;<br /> * from 23.4 before 23.4R2-EVO.
Severity CVSS v4.0: MEDIUM
Last modification:
13/07/2026

CVE-2026-33794

Publication date:
09/07/2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the <br /> <br /> advanced forwarding toolkit (evo-aftmand)<br /> <br /> of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker generating continuous routing updates, resulting in unilist ECMP routes, to crash the <br /> <br /> evo-aftmand process on the PFE, leading to a Denial-of-Service (DoS). The conditions required for successful exploitation are based on a sequence of events that are outside an attacker&amp;#39;s direct control.<br /> <br /> Unified list (unilist) ECMP routes are a specific ECMP behavior where multiple equal-cost routes share a single logical next-hop list entry. The router treats them as one route with multiple next hops and load balances traffic across that unified list. Due to an issue processing unilist ECMP routing updates, internal state corruption may occur, especially in large-scale ECMP unilist deployments, leading to the evo-aftmand process crashing, resulting in an evo-aftmand-bx core. Manual intervention is required to recover by rebooting the system or restarting the FPC.<br /> <br /> This issue affects Junos OS Evolved on PTX :<br /> <br /> <br /> * from 24.4R2-EVO before 24.4R2-S3-EVO;<br /> * from 25.2 before 25.2R2-EVO.
Severity CVSS v4.0: HIGH
Last modification:
13/07/2026

CVE-2026-15270

Publication date:
09/07/2026
A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. Executing a manipulation can lead to least privilege violation. The attack can be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been made available to the public and could be used for attacks.
Severity CVSS v4.0: MEDIUM
Last modification:
13/07/2026

CVE-2026-0278

Publication date:
09/07/2026
Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls.<br /> <br /> <br /> <br /> The Prisma Access Agent on macOS is not affected.
Severity CVSS v4.0: MEDIUM
Last modification:
16/07/2026

CVE-2026-0277

Publication date:
09/07/2026
An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. <br /> <br /> The Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected.
Severity CVSS v4.0: MEDIUM
Last modification:
16/07/2026

CVE-2026-0276

Publication date:
09/07/2026
A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root user.
Severity CVSS v4.0: LOW
Last modification:
16/07/2026

CVE-2026-0275

Publication date:
09/07/2026
A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administrator with access to the macOS local filesystem to perform actions on the device with root privileges. <br /> <br /> This issue only affects Prisma® Browser on macOS.
Severity CVSS v4.0: LOW
Last modification:
14/07/2026

CVE-2026-59148

Publication date:
09/07/2026
Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon&amp;#39;s admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as user-defined mock routes, enabled by default in shipped runtimes, serves Access-Control-Allow-Origin: * with write methods allowed, and has no authentication. Any unauthenticated caller who can reach the mock server port can read MOCKOON_* environment variables, write arbitrary process environment variables through /mockoon-admin/env-vars, rewrite mock route bodies, statuses, and headers through PUT /mockoon-admin/environment, read transaction logs and SSE streams, and purge state. This issue is fixed in version 9.7.0.
Severity CVSS v4.0: Pending analysis
Last modification:
10/07/2026