Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-8801

Publication date:
08/07/2026
Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules).<br /> <br /> This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-60104

Publication date:
08/07/2026
Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organization member to obtain another user&amp;#39;s vault key and a victim-scoped access token by creating a Trusted Device Encryption authentication request, bound to an attacker-controlled public key, that is readable from an unauthenticated endpoint once approved resulting in disclosure of the victim&amp;#39;s vault key and account takeover.
Severity CVSS v4.0: CRITICAL
Last modification:
20/07/2026

CVE-2026-8800

Publication date:
08/07/2026
Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module).<br /> <br /> This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-8651

Publication date:
08/07/2026
Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module).<br /> <br /> This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-8650

Publication date:
08/07/2026
Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module).<br /> <br /> This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-8649

Publication date:
08/07/2026
Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules).<br /> <br /> This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
Severity CVSS v4.0: Pending analysis
Last modification:
10/07/2026

CVE-2026-59936

Publication date:
08/07/2026
pypdf is a free and open-source pure-python PDF library. Prior to 6.14.1, an attacker can craft a PDF with a page content stream containing a not terminated inline image, causing an infinite loop during inline image end marker detection such as when extracting page text. This issue is fixed in version 6.14.1.
Severity CVSS v4.0: HIGH
Last modification:
09/07/2026

CVE-2026-59935

Publication date:
08/07/2026
pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inline image that uses the ASCII85 or ASCIIHex filters, causing an infinite loop during parsing such as when extracting page text. This issue is fixed in version 6.14.2.
Severity CVSS v4.0: HIGH
Last modification:
09/07/2026

CVE-2026-59947

Publication date:
08/07/2026
Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug verbosity, it could print a credential embedded in the username slot of a repository or package URL, such as a GitHub Personal Access Token in https://TOKEN@host/, to debug output because AuthHelper, Url::sanitize, and ProcessExecutor did not sanitize username-only URL credentials. This issue is fixed in versions 2.2.29 and 2.10.2.
Severity CVSS v4.0: Pending analysis
Last modification:
10/07/2026

CVE-2026-59946

Publication date:
08/07/2026
Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve outside the package install directory and cause Composer&amp;#39;s binary installation flow to chmod an existing host file to a world-readable and world-executable mode during composer install, update, or require. This issue is fixed in versions 2.2.29 and 2.10.2.
Severity CVSS v4.0: Pending analysis
Last modification:
10/07/2026

CVE-2026-59948

Publication date:
08/07/2026
Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org or Private Packagist can cause Composer to write attacker-controlled files outside the vendor directory and outside the project during install or update by using an invalid package name that is not correctly validated before dependency-resolution results are written or installed. This issue is fixed in versions 2.2.29 and 2.10.2.
Severity CVSS v4.0: Pending analysis
Last modification:
10/07/2026

CVE-2026-59939

Publication date:
08/07/2026
httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small compressed payload that expands to an arbitrarily large size in memory and causes MemoryError or OOM-kill in the client process. This issue is fixed in version 0.32.0.
Severity CVSS v4.0: Pending analysis
Last modification:
13/07/2026