Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-53363

Publication date:
10/07/2026
In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags()<br /> <br /> iptfs_consume_frags() transfers paged fragments from one socket buffer<br /> to another but fails to propagate the SKBFL_SHARED_FRAG flag. This is<br /> the same class of bug that was fixed in skb_try_coalesce() for<br /> CVE-2026-46300: when fragments backed by read-only page-cache pages are<br /> merged, the marker indicating their shared nature must be preserved so<br /> that ESP can decide correctly whether in-place encryption is safe.<br /> <br /> Apply the same two-line fix used in skb_try_coalesce() to<br /> iptfs_consume_frags().
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-58225

Publication date:
10/07/2026
SQL Injection vulnerability in elixir-ecto postgrex allows an attacker who can influence a LISTEN channel name to inject SQL into the reconnect replay query, causing a denial of service of the notification connection.<br /> <br /> Postgrex.Notifications sanitizes channel names with quote_channel/1, which doubles double quotes so the name is safe inside a double-quoted identifier. This protects the single-statement LISTEN and UNLISTEN paths. On every (re)connect, however, handle_connect/1 replays all registered channels at once by concatenating their LISTEN statements and wrapping them in a dollar-quoted anonymous code block (DO $$BEGIN ... END$$). quote_channel/1 does not escape the $$ dollar-quote delimiter that opens and closes this block.<br /> <br /> The listen/3 guards only reject null bytes and names longer than 63 bytes, so a channel name containing $$ passes validation unchanged. Once such a name is embedded, its $$ prematurely terminates the outer dollar-quoted string and PostgreSQL parses the remainder as additional top-level statements. Because handle_connect/1 runs on every (re)connect, the malformed replay query is rejected each time and the notification connection never re-establishes its subscriptions, silently dropping notifications for every channel sharing that connection.<br /> <br /> An application is affected when it passes untrusted input (for example a tenant or user identifier) as a channel name to Postgrex.Notifications.listen/3. The double-quote doubling prevents forming a fully valid injected statement, so arbitrary SQL execution is not possible, but the corrupted query reliably breaks the shared notification connection for all tenants, resulting in denial of service.<br /> <br /> This issue affects postgrex: from 0.16.0 before 0.22.3.
Severity CVSS v4.0: LOW
Last modification:
10/07/2026

CVE-2026-14461

Publication date:
10/07/2026
mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup() function. An attacker who can influence the TXT response used for AS lookups can trigger this bug by returning a DNS response that is larger than 512 bytes and uses a crafted compression pointer in the answer NAME field. ipinfo_lookup() function uses the length of the response as the end-of-message boundary for dn_expand() function. The result is a reliable crash.<br /> <br /> <br /> This issue exists in the mtr through version 0.96 and it was fixed in commit 48e1794414d338ce47abc0f27c25ade8788af9c3.
Severity CVSS v4.0: MEDIUM
Last modification:
10/07/2026

CVE-2026-9857

Publication date:
10/07/2026
The Invoice123 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the plugin&amp;#39;s API key stored in wp_options, modify invoice plugin settings, and alter WooCommerce tax rate data in the wp_woocommerce_tax_rates table.
Severity CVSS v4.0: Pending analysis
Last modification:
10/07/2026

CVE-2026-41879

Publication date:
10/07/2026
R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to decode superadmin credentials. Critically, this password cannot be changed except by modifying the configuration file.<br /> <br /> This issue was fixed in version v3.17-2000.
Severity CVSS v4.0: HIGH
Last modification:
10/07/2026

CVE-2026-41880

Publication date:
10/07/2026
R-SOFT DMS is vulnerable to OS Command Injection in the Optical Character Recognition (OCR) module. Multiple command execution functions accept user-controllable file paths without proper sanitization before passing them to the system shell via SSH. In current infrastructure the URL encoding neutralizes the injection during the standard web upload flow. An authenticated attacker who is able to trigger the OCR functionality for the uploaded file can execute OS commands within the context of a root user.<br /> <br /> This issue was fixed in version v3.19-2862 and v3.17-2580.
Severity CVSS v4.0: CRITICAL
Last modification:
10/07/2026

CVE-2026-15028

Publication date:
10/07/2026
A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.
Severity CVSS v4.0: Pending analysis
Last modification:
15/07/2026

CVE-2026-13710

Publication date:
10/07/2026
The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets &amp; Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Box widget&amp;#39;s &amp;#39;sg_body_description&amp;#39; parameter in versions up to, and including, 3.2.6. This is due to insufficient input sanitization and output escaping on the description attribute in the render_body() method of the Image_Box_View class — every other attribute used by the method is wrapped in esc_attr(), but the description value is concatenated directly into HTML body context. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity CVSS v4.0: Pending analysis
Last modification:
10/07/2026

CVE-2026-41876

Publication date:
10/07/2026
R-SOFT DMS is vulnerable to OS Command Injection in konwertujAction() function. The document converter executes shell commands using unsanitized file paths and format parameters. This allows an authenticated attacker to execute arbitrary system commands with the privileges of the web server user.<br /> <br /> This issue was fixed in version v3.19-2752 and v3.17-2580.
Severity CVSS v4.0: HIGH
Last modification:
10/07/2026

CVE-2026-41877

Publication date:
10/07/2026
R-SOFT DMS is vulnerable to Stored XSS in file upload functionality. Authenticated attacker can inject arbitrary HTML and JS into the name of the file being uploaded, which will be executed when visiting file list or upload status by other users.<br /> <br /> This issue was fixed in version v3.19-2832 and v3.17-2580.
Severity CVSS v4.0: MEDIUM
Last modification:
10/07/2026

CVE-2026-41878

Publication date:
10/07/2026
R-SOFT DMS is vulnerable to Insecure Direct Object Reference (IDOR) attack in multiple file download endpoints. The application fetches files from the database by ID and serves them to whoever requests them, relying only on session authentication, meaning any valid user can access any file.<br /> <br /> This issue was fixed in version v3.19-2862 and v3.17-2580.
Severity CVSS v4.0: HIGH
Last modification:
10/07/2026

CVE-2026-13010

Publication date:
10/07/2026
The JoomSport – for Sports: Team &amp; League, Football, Hockey &amp; more plugin for WordPress is vulnerable to time-based SQL Injection via &amp;#39;event&amp;#39; Shortcode Attribute in all versions up to, and including, 5.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The shortcode can be embedded in posts or pages by Contributor-level users, making this exploitable by any authenticated user with at least that role.
Severity CVSS v4.0: Pending analysis
Last modification:
10/07/2026