Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-47866

Publication date:
18/07/2026
VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization.<br /> <br /> Affected versions:<br /> 32.1.1 (fixed in 32.1.2)<br /> 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)<br /> 30.1.1 through 30.2.6 (fixed in 30.2.7)<br /> 22.1.1 through 22.1.7 (fixed in 30.2.7)
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-47867

Publication date:
18/07/2026
VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely.<br /> <br /> Affected versions:<br /> 32.1.1 (fixed in 32.1.2)<br /> 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)<br /> 30.1.1 through 30.2.6 (fixed in 30.2.7)<br /> 22.1.1 through 22.1.7 (fixed in 30.2.7)
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-47868

Publication date:
18/07/2026
VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be able to escalate their privileges to run code as root.<br /> <br /> Affected versions:<br /> 32.1.1 (fixed in 32.1.2)<br /> 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)<br /> 30.1.1 through 30.2.6 (fixed in 30.2.7)<br /> 22.1.1 through 22.1.7 (fixed in 30.2.7)
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-47869

Publication date:
18/07/2026
VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code.<br /> <br /> Affected versions:<br /> 32.1.1 (fixed in 32.1.2)<br /> 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)<br /> 30.1.1 through 30.2.6 (fixed in 30.2.7)<br /> 22.1.1 through 22.1.7 (fixed in 30.2.7)
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-47871

Publication date:
18/07/2026
VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to perform directory traversal attacks.<br /> <br /> Affected versions:<br /> 32.1.1 (fixed in 32.1.2)<br /> 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)<br /> 30.1.1 through 30.2.6 (fixed in 30.2.7)<br /> 22.1.1 through 22.1.7 (fixed in 30.2.7)
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-47870

Publication date:
18/07/2026
VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network access may be able to execute remote code.<br /> <br /> Affected versions:<br /> 32.1.1 (fixed in 32.1.2)<br /> 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)<br /> 30.1.1 through 30.2.6 (fixed in 30.2.7)<br /> 22.1.1 through 22.1.7 (fixed in 30.2.7)
Severity CVSS v4.0: Pending analysis
Last modification:
24/07/2026

CVE-2026-16083

Publication date:
18/07/2026
A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of the file pkg/channels/line/line.go of the component LINE Webhook. The manipulation results in authentication bypass by capture-replay. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The reported GitHub issue was closed automatically with the label "not planned" by a bot.
Severity CVSS v4.0: MEDIUM
Last modification:
20/07/2026

CVE-2026-16082

Publication date:
18/07/2026
A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun of the file pkg/agent/pipeline_execute.go. The manipulation of the argument cwe leads to time-of-check time-of-use. The attack must be carried out locally. The exploit is publicly available and might be used. The reported GitHub issue was closed automatically with the label "not planned" by a bot.
Severity CVSS v4.0: LOW
Last modification:
22/07/2026

CVE-2026-16081

Publication date:
18/07/2026
A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file web/backend/api/auth.go. Executing a manipulation can lead to cross-site request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called 4b0229351678f479429b8d8b19207757266f246b. Applying a patch is advised to resolve this issue.
Severity CVSS v4.0: LOW
Last modification:
20/07/2026

CVE-2026-16077

Publication date:
18/07/2026
A vulnerability was found in AstrBotDevs AstrBot up to 4.25.5. Impacted is the function _normalize_rw_path of the file astrbot/core/tools/computer_tools/fs.py of the component Filesystem Computer-Use Tool. Performing a manipulation results in link following. The attack is only possible with local access. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity CVSS v4.0: LOW
Last modification:
20/07/2026

CVE-2026-16076

Publication date:
18/07/2026
A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the function OpenApiRoute.chat_send of the file astrbot/dashboard/routes/open_api.py of the component API. Such manipulation of the argument Username leads to authentication bypass by spoofing. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity CVSS v4.0: LOW
Last modification:
20/07/2026

CVE-2026-9734

Publication date:
18/07/2026
The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the storeInfo function. This makes it possible for unauthenticated attackers to modify the plugin&amp;#39;s Zoho CRM integration settings, replacing the configured data center, client ID, client secret, and user email credentials with attacker-controlled values via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026