Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-57243

Publication date:
08/07/2026
During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document status. Subsequently, with outdated page information, the application attempts to access invalid addresses, causing the application to crash.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-57241

Publication date:
08/07/2026
The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related objects within the application to lose synchronization; however, the renderer still trusts the outdated page count, and eventually the application crashes due to out-of-bounds access.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-57237

Publication date:
08/07/2026
When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the underlying objects referenced by the program to become invalid. Eventually, it reads an illegal memory address, which leads to the crash of the application.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-57238

Publication date:
08/07/2026
After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the invalid object, which caused the application to crash.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-57240

Publication date:
08/07/2026
When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old field pointers, resulting in invalid pointer references and causing the application to crash.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-57239

Publication date:
08/07/2026
The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\SYSTEM.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-56001

Publication date:
08/07/2026
A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code within the X server cont
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-13127

Publication date:
08/07/2026
The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the invalidation of the page objects. However, the thumbnails still use the invalid page objects, ultimately causing the application to crash.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-13128

Publication date:
08/07/2026
Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the relevant properties of the document view, eventually leading to the crash of the application.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-13129

Publication date:
08/07/2026
When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid form object when accessing the field property path. Eventually, the application crashes due to reading an invalid pointer.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-13126

Publication date:
08/07/2026
The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a write operation on the invalid pop-up annotations, resulting in the program crashing.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-56000

Publication date:
08/07/2026
Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.
Severity CVSS v4.0: CRITICAL
Last modification:
09/07/2026