Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-5242

Publication date:
15/06/2026
Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy Library allows Code Injection.<br /> <br /> This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2026

CVE-2026-5079

Publication date:
15/06/2026
Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form data. The append-field dependency parses bracket notation in field names with no limit on nesting depth, allowing an attacker to force allocation of deeply nested object structures that consume CPU and memory. A single HTTP request with a crafted multipart body is sufficient to exploit this.<br /> <br /> Patches: Users should upgrade to multer 2.2.0 (2.x line) or 3.0.0-alpha.2 (3.x prerelease) and configure the new limits.fieldNestingDepth option to the minimum depth their application requires.<br /> <br /> Workarounds: Set limits.fields to a reasonable value to reduce the number of fields an attacker can send per request. This does not fully mitigate the issue but limits the impact.
Severity CVSS v4.0: Pending analysis
Last modification:
16/06/2026

CVE-2026-6517

Publication date:
15/06/2026
Mattermost Desktop App versions
Severity CVSS v4.0: Pending analysis
Last modification:
16/06/2026

CVE-2026-52704

Publication date:
15/06/2026
Improper Control of Generation of Code (&amp;#39;Code Injection&amp;#39;) vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion.<br /> <br /> This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0.8.
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2026

CVE-2026-48969

Publication date:
15/06/2026
Subscriber Broken Access Control in Really Simple SSL
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2026

CVE-2026-49062

Publication date:
15/06/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Exploitation.<br /> <br /> This issue affects Faust.Js: from n/a through 1.8.7.
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2026

CVE-2026-49064

Publication date:
15/06/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Data.<br /> <br /> This issue affects GetPaid: from n/a through 2.8.49.
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2026

CVE-2026-49111

Publication date:
15/06/2026
Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation.<br /> <br /> This issue affects Masteriyo - LMS: from n/a through 2.2.0.
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2026

CVE-2025-64215

Publication date:
15/06/2026
Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Constrained by ACLs.<br /> <br /> This issue affects MasterStudy LMS Pro: from n/a before 4.7.16.
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2026

CVE-2016-20084

Publication date:
15/06/2026
WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities that allow unauthenticated attackers to modify calendar settings and inject persistent cross-site scripting payloads through the admin.php page parameters. Attackers can inject malicious JavaScript into the &amp;#39;ict&amp;#39; and &amp;#39;ics&amp;#39; options or the calendar &amp;#39;name&amp;#39; parameter via GET requests to execute arbitrary scripts when the calendar is displayed or accessed in the administration interface.
Severity CVSS v4.0: MEDIUM
Last modification:
15/06/2026

CVE-2018-25436

Publication date:
15/06/2026
WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files by exploiting the upload-package.php endpoint. Attackers can submit POST requests with malicious file extensions to the upload handler, which moves files without validation to the plugin upload directory, enabling remote code execution.
Severity CVSS v4.0: CRITICAL
Last modification:
15/06/2026

CVE-2018-25437

Publication date:
15/06/2026
WordPress CherryFramework Themes 3.1.4 contains an information disclosure vulnerability that allows unauthenticated attackers to download sensitive backup files by accessing the download_backup.php endpoint. Attackers can directly access the download_backup.php script in the admin/data_management directory to obtain ZIP archives containing the entire wp-content/themes directory contents.
Severity CVSS v4.0: HIGH
Last modification:
15/06/2026