Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-13693

Publication date:
21/07/2026
The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a notification email, allowing unauthenticated attackers to read arbitrary server files such as the WordPress configuration file.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2026

CVE-2026-13694

Publication date:
21/07/2026
The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing unauthenticated attackers to re-trigger a form's configured workflow actions such as notification emails and integrations.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2026

CVE-2026-13439

Publication date:
21/07/2026
The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier ('sid') as the password reset token stored in wp_emsfb_temp_links, combined with a publicly-accessible nonce refresh endpoint (Emsfb/v1/nonce/refresh) that issues valid WordPress REST nonces to unauthenticated visitors. This makes it possible for unauthenticated attackers to reset the password of any WordPress user — including administrators — by scraping the public sid from a published login form page, submitting a recovery request for any known user email via Emsfb/v1/forms/message/add, and then calling Emsfb/v1/forms/recovery/efb_set_password with the known sid to set an arbitrary new password and gain full administrator access.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2026

CVE-2026-15782

Publication date:
21/07/2026
The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the OptinMonster plugin to be installed and configured with an active inline campaign that outputs matching #om-{id} markup on the target page, as the WPForms handler only fires when OptinMonster emits its 'om.Campaign.load' event.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2026

CVE-2026-15927

Publication date:
21/07/2026
A flaw was found in Red Hat Quay&amp;#39;s repository-level mirror configuration<br /> feature. The POST and PUT handlers in endpoints/api/mirror.py accept an<br /> external_reference parameter without SSRF validation, unlike the<br /> organization-level mirror handlers which apply validate_external_registry_url().<br /> A repository administrator can supply a crafted hostname that causes the Quay<br /> mirror worker to make requests via Skopeo to internal network services, cloud<br /> metadata endpoints, or other resources not intended to be reachable from the<br /> Quay application.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2026

CVE-2026-3182

Publication date:
21/07/2026
Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2026

CVE-2026-15812

Publication date:
21/07/2026
A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected:
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-16266

Publication date:
21/07/2026
Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript prototype chain by supplying a crafted property path containing special keys such as __proto__.
Severity CVSS v4.0: MEDIUM
Last modification:
23/07/2026

CVE-2026-15811

Publication date:
21/07/2026
A vulnerability was found in kronosnet&amp;#39;s (version
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2023-37507

Publication date:
21/07/2026
HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.
Severity CVSS v4.0: MEDIUM
Last modification:
29/07/2026

CVE-2026-15156

Publication date:
21/07/2026
The Essential Addons for Elementor – Popular Elementor Templates &amp; Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2023-37508

Publication date:
21/07/2026
HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain browser weaknesses are present.
Severity CVSS v4.0: LOW
Last modification:
29/07/2026