Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-54920

Publication date:
25/08/2026
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a reachable assertion failure in the HTJ2K decode path allows a crafted HTJ2K-compressed EXR file to cause an unconditional process abort in any application that calls exr_start_read() on untrusted input, resulting in denial of service. The crash is triggered by a QCD marker whose lower five bits are zero, which OpenEXR passes into the vendored OpenJPH library while constructing the codestream and evaluating its quantization delta parameters. OpenJPH uses an assertion rather than a recoverable error to validate those bits, so any invalid value calls abort() directly and cannot be intercepted by surrounding error handling, a problem compounded by OpenEXR wrapping only its internal HT header parser in error handling while leaving the later codestream read and construction calls unprotected. This issue has been resolved in version 3.4.13.
Severity CVSS v4.0: Pending analysis
Last modification:
25/08/2026

CVE-2026-53532

Publication date:
24/08/2026
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a crafted HTJ2K-compressed EXR file causes an unconditional process abort in any application that calls exr_start_read() on untrusted input, resulting in denial of service. The crash is triggered by a QCD marker whose lower five bits are zero, which OpenEXR passes into the vendored OpenJPH library while constructing the codestream and evaluating its quantization delta parameters. OpenJPH uses an assertion rather than a recoverable error to validate those bits, so any invalid value calls abort() directly and cannot be intercepted by surrounding error handling, a problem compounded by OpenEXR wrapping only its internal HT header parser in error handling while leaving the later codestream read and construction calls unprotected. This issue has been resolved in version 3.4.13.
Severity CVSS v4.0: HIGH
Last modification:
24/08/2026

CVE-2026-78434

Publication date:
24/08/2026
A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endpoint. This manipulation causes missing authentication. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity CVSS v4.0: MEDIUM
Last modification:
24/08/2026

CVE-2026-78435

Publication date:
24/08/2026
A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Such manipulation of the argument data1 leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity CVSS v4.0: LOW
Last modification:
24/08/2026

CVE-2026-78284

Publication date:
24/08/2026
Unauthenticated Arbitrary File Deletion in MasterStudy LMS
Severity CVSS v4.0: Pending analysis
Last modification:
25/08/2026

CVE-2026-78263

Publication date:
24/08/2026
Unauthenticated Cross Site Scripting (XSS) in Event Tickets
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2026

CVE-2026-78266

Publication date:
24/08/2026
Subscriber Broken Access Control in AutomatorWP
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2026

CVE-2026-78267

Publication date:
24/08/2026
Unauthenticated Privilege Escalation in TranslatePress
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2026

CVE-2026-78268

Publication date:
24/08/2026
Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2026

CVE-2026-78282

Publication date:
24/08/2026
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2026

CVE-2026-78264

Publication date:
24/08/2026
Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks
Severity CVSS v4.0: Pending analysis
Last modification:
25/08/2026

CVE-2026-78265

Publication date:
24/08/2026
Unauthenticated PHP Object Injection in The Events Calendar
Severity CVSS v4.0: Pending analysis
Last modification:
25/08/2026