Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-13397

Publication date:
16/07/2026
HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes.<br /> <br /> The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever.<br /> <br /> Nameless attributes such as "" or unbalanced quotes "" can trigger this condition.<br /> <br /> Note that the latest version available on CPAN is version 0.02. Newer versions are available on the git repository.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2026-44596

Publication date:
16/07/2026
Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an unauthenticated remote attacker could perform unlimited password-guessing attempts against any user account, significantly increasing the risk of successful brute-force attacks. This issue is fixed in versions 5.12.7 and 5.13.0.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2026-3031

Publication date:
16/07/2026
Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library.<br /> <br /> Image::EPEG includes Epeg 0.9.0 that was last updated in 2004.<br /> <br /> Epeg is a fast JPEG thumbnail library that was once part of the Englightenment Project.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2026-44595

Publication date:
16/07/2026
Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java, so any authenticated user, even one with low or no privileges, could enumerate all user accounts in the system including their usernames, superuser status, and group memberships. This issue is fixed in versions 5.12.7 and 5.13.0.
Severity CVSS v4.0: Pending analysis
Last modification:
18/07/2026

CVE-2026-10589

Publication date:
16/07/2026
A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.
Severity CVSS v4.0: MEDIUM
Last modification:
16/07/2026

CVE-2026-10590

Publication date:
16/07/2026
A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrarily trigger a System Management Interrupt handler.
Severity CVSS v4.0: MEDIUM
Last modification:
16/07/2026

CVE-2026-13103

Publication date:
16/07/2026
A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code.
Severity CVSS v4.0: HIGH
Last modification:
16/07/2026

CVE-2026-10587

Publication date:
16/07/2026
A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode.
Severity CVSS v4.0: MEDIUM
Last modification:
16/07/2026

CVE-2026-10588

Publication date:
16/07/2026
A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.
Severity CVSS v4.0: MEDIUM
Last modification:
16/07/2026

CVE-2025-45870

Publication date:
16/07/2026
LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated user to exploit path traversal flaws in the fileExt parameter, enabling unauthorized access to sensitive files outside the designated directories.
Severity CVSS v4.0: Pending analysis
Last modification:
20/07/2026

CVE-2026-63082

Publication date:
16/07/2026
Perfect Support Ticketing &amp; Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers with Agent-level privileges to manipulate the Support Agent assignment field of tickets by bypassing intended authorization checks. Attackers can add or remove any user, including Superadmin accounts, from the Support Agent field of any ticket to which they are assigned, circumventing role-based access controls.
Severity CVSS v4.0: MEDIUM
Last modification:
16/07/2026

CVE-2026-63081

Publication date:
16/07/2026
Perfect Support Ticketing &amp; Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious payloads into the Notes field of assigned support tickets. Attackers can store malicious scripts that execute in the browser context of any user who views the affected ticket notes, including Superadmin users, enabling session hijacking or unauthorized actions on behalf of the victim.
Severity CVSS v4.0: MEDIUM
Last modification:
18/07/2026