Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-63768

Publication date:
20/07/2026
cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows attackers to redirect users to arbitrary URLs by crafting malicious state parameters. Attackers can exploit the unsigned state parameter and onErrorReturnTo field to silently redirect visitors from the trusted domain to attacker-controlled URLs for phishing attacks.
Severity CVSS v4.0: MEDIUM
Last modification:
23/07/2026

CVE-2026-63108

Publication date:
20/07/2026
Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions inside parameter expansion defaults. The command parser in parse-command.ts replaces parameter expansions with opaque placeholders before extracting command substitutions, causing the containsDangerousSubstitution guard to miss nested payloads, which are then auto-approved based on the outer allowlisted command prefix and executed by the shell via execa, enabling arbitrary command execution.
Severity CVSS v4.0: HIGH
Last modification:
23/07/2026

CVE-2026-63769

Publication date:
20/07/2026
Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe internal network services, enumerate ports via error signatures, and access cloud metadata endpoints to retrieve sensitive credentials.
Severity CVSS v4.0: MEDIUM
Last modification:
23/07/2026

CVE-2026-63771

Publication date:
20/07/2026
Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forwarded-Prefix HTTP header used in Set-Cookie path attributes. Attackers can exploit a misconfigured reverse proxy to downgrade SameSite protection and enable cross-origin authenticated requests, bypassing cookie security controls.
Severity CVSS v4.0: MEDIUM
Last modification:
23/07/2026

CVE-2026-63770

Publication date:
20/07/2026
Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler that allows unauthenticated attackers to bypass brute-force lockout protections by supplying arbitrary values in the X-Forwarded-For request header when the server proxied option is enabled. Attackers can manipulate the leftmost value of the X-Forwarded-For header to make each login attempt appear to originate from a distinct IP address, preventing the per-IP failed-login counter from reaching the lockout threshold and enabling unlimited credential guessing against the authentication endpoint.
Severity CVSS v4.0: HIGH
Last modification:
23/07/2026

CVE-2026-61424

Publication date:
20/07/2026
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds
Severity CVSS v4.0: CRITICAL
Last modification:
23/07/2026

CVE-2026-61425

Publication date:
20/07/2026
Joomla Extension - balbooa.com - Authentication bypass in Gridbox
Severity CVSS v4.0: CRITICAL
Last modification:
23/07/2026

CVE-2026-61900

Publication date:
20/07/2026
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads
Severity CVSS v4.0: CRITICAL
Last modification:
23/07/2026

CVE-2026-61901

Publication date:
20/07/2026
Joomla Extension - hikashop.com - Open redirect in Hikashop
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-62414

Publication date:
20/07/2026
Joomla Extension - joomlack.fr - Improper access control in Page Builder CK
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-63107

Publication date:
20/07/2026
LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey template endpoint that allows authenticated users to cause the server to issue arbitrary HTTP requests by supplying a manipulated Host header. Attackers can exploit the unsanitized use of the HTTP Host header in the getTemplateData() function to reach internal network services, cloud metadata endpoints, and extract sensitive credentials such as IAM tokens from instance metadata services.
Severity CVSS v4.0: MEDIUM
Last modification:
23/07/2026

CVE-2026-60027

Publication date:
20/07/2026
Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder
Severity CVSS v4.0: HIGH
Last modification:
23/07/2026