Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-15945

Publication date:
16/07/2026
A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2026-15737

Publication date:
16/07/2026
AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform.<br /> <br /> <br /> <br /> Unintended logging of sensitive user content in the OpenTelemetry instrumentation in AWS Bedrock AgentCore Python SDK versions 1.4.8 and 1.5.0 might allow a local authenticated user with access to CloudWatch Logs to access raw user prompts and agent responses containing sensitive data via span attributes. The SDK wrote raw user prompts and complete agent responses into OpenTelemetry span attributes on every invocation without filtering or masking. These spans flow into the customer&amp;#39;s aws/spans CloudWatch log group, exposing sensitive content to any principal with log read access.<br /> <br /> <br /> <br /> We recommend you upgrade to version 1.5.1 or later. Users who ran affected versions should also review and purge sensitive content from their aws/spans CloudWatch log groups.
Severity CVSS v4.0: MEDIUM
Last modification:
17/07/2026

CVE-2021-27137

Publication date:
16/07/2026
An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request).
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-9046

Publication date:
16/07/2026
A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a non‑system partition, could allow a local user to execute arbitrary code.
Severity CVSS v4.0: HIGH
Last modification:
16/07/2026

CVE-2026-63086

Publication date:
16/07/2026
text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compatible multimodal chat completions endpoint that allows unauthenticated network attackers to coerce the server into issuing arbitrary HTTP GET requests by supplying a crafted image_url value in chat message content. The fetch_image function in router/src/validation.rs performs no validation of private, loopback, link-local, or cloud metadata target addresses, and the reqwest HTTP client follows redirects by default, enabling attackers to bypass scheme checks via redirect chains to reach internal services and cloud instance-metadata endpoints for internal port scanning and credential theft.
Severity CVSS v4.0: MEDIUM
Last modification:
16/07/2026

CVE-2026-63088

Publication date:
16/07/2026
stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated network-accessible attackers to bypass the DNS-based IP blocklist by exploiting incomplete address validation in the url_is_blacklisted function, which inspects only the first resolved address while the underlying HTTP client iterates all cached addresses.
Severity CVSS v4.0: HIGH
Last modification:
16/07/2026

CVE-2026-6511

Publication date:
16/07/2026
During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that could allow a local authenticated user to access files owned by a different user on the same system.
Severity CVSS v4.0: MEDIUM
Last modification:
16/07/2026

CVE-2026-57073

Publication date:
16/07/2026
HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead.<br /> <br /> The parserc_parse function attempts to check for multicharacter strings such as "" without checking that the offsets are within the buffer.<br /> <br /> Truncated strings such as "
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2026-63087

Publication date:
16/07/2026
Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install endpoint using hardcoded default stack_id and org_id values present in the public source tree. Attackers can leverage the acquired token to authenticate against all internal API endpoints, create arbitrary Admin users via the user-context header bootstrap path, revoke the legitimate plugin token, and redirect OnCall-to-Grafana API calls to an attacker-controlled host by overwriting the organization&amp;#39;s grafana_url and api_token.
Severity CVSS v4.0: CRITICAL
Last modification:
17/07/2026

CVE-2026-57074

Publication date:
16/07/2026
XML::Bare versions through 0.53 for Perl have an unbounded character lookahead.<br /> <br /> The parserc_parse function attempts to check for multicharacter strings such as "" without checking that the offsets are within the buffer.<br /> <br /> Truncated strings such as "
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2026-63085

Publication date:
16/07/2026
Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticated non-admin users to escalate privileges by exploiting unenforced field restrictions on nested relational save operations. Attackers can modify sensitive User record fields such as roles and group by submitting changes through a related entity&amp;#39;s save path, bypassing the USER_RESTRICTED_FIELDS control and causing the JPA persistence layer to flush attacker-supplied admin role and group assignments on commit.
Severity CVSS v4.0: HIGH
Last modification:
17/07/2026

CVE-2026-55406

Publication date:
16/07/2026
Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.7.0, a soundness bug in the OwnedView type allowed safe Rust code to trigger a use-after-free: the OwnedView::decode constructor transmuted a borrowed slice to &amp;&amp;#39;static [u8], and the Deref implementation exposed the promoted &amp;#39;static lifetime on borrowed view fields (such as &amp;&amp;#39;static str and &amp;&amp;#39;static [u8]) to callers, so the borrow checker permitted those references to outlive the OwnedView; once the OwnedView was dropped and its backing buffer freed, the references became dangling, enabling memory corruption, information disclosure of freed heap contents, and cross-thread misuse without any unsafe code in the calling application. This issue is fixed in version 0.7.0.
Severity CVSS v4.0: MEDIUM
Last modification:
16/07/2026