Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-49899

Publication date:
16/07/2026
An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.
Severity CVSS v4.0: Pending analysis
Last modification:
18/07/2026

CVE-2026-22752

Publication date:
16/07/2026
Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server.<br /> <br /> This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1.3.0 through 1.3.10.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2026

CVE-2026-6423

Publication date:
16/07/2026
A local privilege escalation vulnerability in ESET Inspect Connector. <br /> The vulnerability was caused by improper authentication in an IPC channel.
Severity CVSS v4.0: HIGH
Last modification:
16/07/2026

CVE-2026-6424

Publication date:
16/07/2026
Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the system
Severity CVSS v4.0: MEDIUM
Last modification:
16/07/2026

CVE-2026-7543

Publication date:
16/07/2026
The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the &amp;#39;fields&amp;#39; parameter in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2026-58078

Publication date:
16/07/2026
Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro
Severity CVSS v4.0: HIGH
Last modification:
23/07/2026

CVE-2026-15610

Publication date:
16/07/2026
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 8.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to trigger arbitrary re-embedding of stored RAG documents, modifying the rag_documents table and consuming the site owner&amp;#39;s paid third-party AI API credits (OpenAI, Gemini, OpenRouter, or xAI).
Severity CVSS v4.0: Pending analysis
Last modification:
16/07/2026

CVE-2026-15727

Publication date:
16/07/2026
The WP Bulk Delete plugin for WordPress is vulnerable to generic SQL Injection via the &amp;#39;delete_user_roles&amp;#39; parameter in all versions up to, and including, 1.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. wp_unslash() is applied to the raw POST body before parse_str() decomposes it, stripping WordPress magic-quotes protection and leaving attacker-controlled values fully unescaped prior to reaching the SQL sink.
Severity CVSS v4.0: Pending analysis
Last modification:
16/07/2026

CVE-2026-15350

Publication date:
16/07/2026
The The Cache Purger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.20. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to permanently truncate the plugin&amp;#39;s cache-purge audit log (wp-content/purge.log), destroying the entire cache-purge audit history. The tcp_log_purge nonce is rendered in the admin bar on frontend pages accessible to all authenticated users including subscribers, meaning any authenticated user possesses the nonce required to trigger the deletion.
Severity CVSS v4.0: Pending analysis
Last modification:
16/07/2026

CVE-2026-15651

Publication date:
16/07/2026
The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the &amp;#39;filtersource&amp;#39; parameter in all versions up to, and including, 14.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Severity CVSS v4.0: Pending analysis
Last modification:
16/07/2026

CVE-2026-15407

Publication date:
16/07/2026
The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite or delete the generated CSS stylesheet file of arbitrary posts, including private and draft posts owned by other users, and modify plugin-scoped font options. The required CSRF nonce (tf_nonce) is emitted on public front-end builder pages via wp_localize_script, making it trivially obtainable by any authenticated user visiting such a page.
Severity CVSS v4.0: Pending analysis
Last modification:
18/07/2026

CVE-2026-15005

Publication date:
16/07/2026
The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on the execTemplate function. This makes it possible for unauthenticated attackers to execute arbitrary PHP code on the server by supplying a php://filter stream wrapper URI as the &amp;#39;template&amp;#39; parameter, which bypasses path validation and is passed directly to the include sink in execTemplate() via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Severity CVSS v4.0: Pending analysis
Last modification:
16/07/2026