Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-58306

Publication date:
09/07/2026
Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.<br /> <br /> This issue affects Escargot: before ef525f337fafddecde77a3c426212a84bb20cb98.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-58307

Publication date:
09/07/2026
Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Data Manipulation.<br /> <br /> This issue affects Escargot: before 2dee22f5c7b8bf31cb7252d7731fae8c07f2842c.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-59691

Publication date:
09/07/2026
A heap buffer overflow vulnerability was found in GStreamer&amp;#39;s rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type mismatch causes an out-of-bounds heap write that can lead to denial of service (process crash) and potential memory corruption.
Severity CVSS v4.0: Pending analysis
Last modification:
19/08/2026

CVE-2026-59692

Publication date:
09/07/2026
A stack buffer overflow vulnerability was found in GStreamer&amp;#39;s DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
19/08/2026

CVE-2026-56288

Publication date:
09/07/2026
GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) data structures, causing the application to pass a NULL pointer to fwrite() during patch processing.<br /> An attacker can trigger this condition with a malicious patch file, causing the utility to crash and resulting in a denial of service.<br /> <br /> <br /> <br /> This issue has been fixed in the commit e6d6a4e021660679d7fc9150f981d4920f722313
Severity CVSS v4.0: MEDIUM
Last modification:
13/07/2026

CVE-2026-56289

Publication date:
09/07/2026
GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position.<br /> This results in excessive CPU consumption and prevents the process from completing.<br /> An attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination.<br /> <br /> <br /> <br /> This issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9
Severity CVSS v4.0: MEDIUM
Last modification:
13/07/2026

CVE-2026-56291

Publication date:
09/07/2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension
Severity CVSS v4.0: CRITICAL
Last modification:
24/07/2026

CVE-2026-4298

Publication date:
09/07/2026
The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. This is due to the dsgvo_reset_policy_service_func() function lacking both capability checks and nonce verification while processing user-supplied parameters to reset plugin options. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset all customized privacy policy content including cookie notices, Google Analytics policies, Facebook policies, and YouTube policies to their default values.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-4275

Publication date:
09/07/2026
The Divi Torque Lite – Divi Theme, Divi Builder &amp; Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. This is due to the use of &amp;#39;__return_true&amp;#39; as the permission_callback for the /install_plugin and /activate_plugin REST API endpoints, which bypasses WordPress&amp;#39;s built-in REST API nonce verification. Although the endpoint callbacks contain internal current_user_can() checks, the absence of nonce verification means that a forged cross-site request from a logged-in administrator&amp;#39;s browser will pass the capability check via the admin&amp;#39;s session cookies. This makes it possible for unauthenticated attackers to install arbitrary plugins from WordPress.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-50644

Publication date:
09/07/2026
SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all rights can inject SQL commands into the audit configuration form which is then saved. The execution is triggered when the audit functionality is accessed (by the attacker or another user).<br /> <br /> This issue was fixed in version 1.56.01.
Severity CVSS v4.0: HIGH
Last modification:
09/07/2026

CVE-2026-12428

Publication date:
09/07/2026
The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_values() function in the /wp-json/acf-field-blocks/v1/values REST endpoint in versions up to, and including, 1.6.2. The permission_callback only verifies the generic publish_posts capability and the handler passes a user-supplied id parameter directly to get_field_objects() without verifying that the requesting user is authorized to read the target object. This makes it possible for authenticated attackers, with Author-level access and above, to read ACF field values from arbitrary posts (including private posts, drafts, posts by other users, and other ACF-supported objects) that they should not have access to.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-13441

Publication date:
09/07/2026
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the &amp;#39;new_event_type_background_color&amp;#39; parameter in all versions up to, and including, 4.3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the plugin&amp;#39;s Guest Submissions setting (allow_submission_by_anonymous_user) to be enabled, which allows unauthenticated attackers to submit event types via the frontend form; when that setting is disabled, exploitation requires at minimum a subscriber-level authenticated account.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026