Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-61425

Publication date:
20/07/2026
Joomla Extension - balbooa.com - Authentication bypass in Gridbox
Severity CVSS v4.0: CRITICAL
Last modification:
23/07/2026

CVE-2026-61900

Publication date:
20/07/2026
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads
Severity CVSS v4.0: CRITICAL
Last modification:
23/07/2026

CVE-2026-61901

Publication date:
20/07/2026
Joomla Extension - hikashop.com - Open redirect in Hikashop
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-62414

Publication date:
20/07/2026
Joomla Extension - joomlack.fr - Improper access control in Page Builder CK
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-63107

Publication date:
20/07/2026
LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey template endpoint that allows authenticated users to cause the server to issue arbitrary HTTP requests by supplying a manipulated Host header. Attackers can exploit the unsanitized use of the HTTP Host header in the getTemplateData() function to reach internal network services, cloud metadata endpoints, and extract sensitive credentials such as IAM tokens from instance metadata services.
Severity CVSS v4.0: MEDIUM
Last modification:
23/07/2026

CVE-2026-60027

Publication date:
20/07/2026
Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder
Severity CVSS v4.0: HIGH
Last modification:
23/07/2026

CVE-2026-60028

Publication date:
20/07/2026
Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder
Severity CVSS v4.0: HIGH
Last modification:
23/07/2026

CVE-2026-60029

Publication date:
20/07/2026
Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder
Severity CVSS v4.0: MEDIUM
Last modification:
23/07/2026

CVE-2026-60030

Publication date:
20/07/2026
Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder
Severity CVSS v4.0: HIGH
Last modification:
23/07/2026

CVE-2026-60031

Publication date:
20/07/2026
Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder
Severity CVSS v4.0: MEDIUM
Last modification:
23/07/2026

CVE-2026-60032

Publication date:
20/07/2026
Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia
Severity CVSS v4.0: CRITICAL
Last modification:
23/07/2026

CVE-2026-60033

Publication date:
20/07/2026
Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension
Severity CVSS v4.0: MEDIUM
Last modification:
23/07/2026