Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-45612

Publication date:
16/07/2026
rz-libdemangle is a Rizin library for demangling symbols. Prior to 6bf56d3, the Rust demangler in src/rust/rust_v0.c can perform an out-of-bounds read when the demangler structure is not yet initialized. This issue is fixed in commit 6bf56d3.
Severity CVSS v4.0: Pending analysis
Last modification:
16/07/2026

CVE-2026-45795

Publication date:
16/07/2026
The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server accepts unsigned JWE request objects because JwtAuthorizationRequest skips inner signature validation when jwe.getSignedJWTPayload() returns null, and AuthzRequestService.processRequestObject() does not reject the unrecognized RSA-OAEP algorithm when forceSignedRequestObject=true. This issue is fixed in version 2.0.0.
Severity CVSS v4.0: Pending analysis
Last modification:
16/07/2026

CVE-2026-44632

Publication date:
16/07/2026
Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory, which dynamically compiled and evaluated user-controlled algorithm text through the Janino compiler without enforcing a secure sandbox, so an authenticated user with the ChangeMissionDatabase privilege could override an existing algorithm's text via the mission database REST API and inject Java code (for example using java.lang.Runtime) to achieve remote code execution on the underlying host operating system. This issue is fixed in versions 5.12.7 and 5.13.0, which disable algorithm editing by default.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2026-45325

Publication date:
16/07/2026
Gestor de Oferta is a web application for managing mobility service offerings. Prior to 20260509.0340.15, @tmlmobilidade/utils has a prototype pollution vulnerability in setValueAtPath() in packages/utils/src/generic/value-at-path.ts because unsafe path segments are not blocked. This issue is fixed in version 20260509.0340.15.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2026-45367

Publication date:
16/07/2026
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.7, the FHIRPathEngine implementation passes user-controlled regular expressions from matches(), matchesFull(), and replaceMatches() to Java regex operations without effective timeouts, allowing catastrophic backtracking and denial of service. This issue is fixed in version 6.9.7.
Severity CVSS v4.0: Pending analysis
Last modification:
18/07/2026

CVE-2026-46562

Publication date:
16/07/2026
Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed without a ClassFilter, so a user with the ChangeMissionDatabase privilege could override an algorithm through the MdbOverrideApi.updateAlgorithm endpoint and supply JavaScript that reaches arbitrary Java classes (for example Java.type("java.lang.Runtime").getRuntime().exec(...)) to execute arbitrary OS commands as the Yamcs process; in the default configuration with no security.yaml the built-in guest user has superuser=true, making the issue reachable without authentication. This issue is fixed in versions 5.12.7 and 5.13.0, which disable algorithm editing by default.
Severity CVSS v4.0: Pending analysis
Last modification:
20/07/2026

CVE-2026-45576

Publication date:
16/07/2026
zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores attacker-controlled WebDAV or zrok drive paths such as /../outside.txt in the source inventory and passes them to FilesystemTarget.WriteStream, allowing the sync pipeline to write files outside the selected local filesystem destination root. This issue is fixed in version 2.0.3.
Severity CVSS v4.0: HIGH
Last modification:
20/07/2026

CVE-2026-45568

Publication date:
16/07/2026
zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to urllib.parse.urljoin, allowing the requested path to replace the configured target host and causing requests.request to return a server-side response from an attacker-chosen URL. This issue is fixed in version 2.0.3.
Severity CVSS v4.0: CRITICAL
Last modification:
20/07/2026

CVE-2026-13104

Publication date:
16/07/2026
A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code with elevated privileges.
Severity CVSS v4.0: HIGH
Last modification:
16/07/2026

CVE-2026-14371

Publication date:
16/07/2026
The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing remote PowerShell commands.
Severity CVSS v4.0: HIGH
Last modification:
16/07/2026

CVE-2026-13401

Publication date:
16/07/2026
XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes.<br /> <br /> The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever.<br /> <br /> Nameless attributes such as "" or unbalanced quotes "" can trigger this condition.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2026-13397

Publication date:
16/07/2026
HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes.<br /> <br /> The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever.<br /> <br /> Nameless attributes such as "" or unbalanced quotes "" can trigger this condition.<br /> <br /> Note that the latest version available on CPAN is version 0.02. Newer versions are available on the git repository.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026