Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-59708

Publication date:
07/07/2026
The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing unauthenticated access to full portfolio data. Attackers with a private access ID can retrieve sensitive portfolio information including holdings, quantities, buy prices, and performance metrics without authentication.
Severity CVSS v4.0: HIGH
Last modification:
10/07/2026

CVE-2026-59800

Publication date:
07/07/2026
9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-install endpoint (this route is not covered by the dashboard middleware matcher, so no authorization check is applied). The sudoPassword field from the request body is written to the stdin of a 'sudo -S sh' child process. When sudo does not prompt for a password (the process runs as root, NOPASSWD is configured, or a recent sudo timestamp cache exists), the sudoPassword value is interpreted by sh as a shell command, allowing a remote unauthenticated attacker to execute arbitrary OS commands. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-07-04 (UTC).
Severity CVSS v4.0: CRITICAL
Last modification:
10/07/2026

CVE-2026-48954

Publication date:
07/07/2026
Improper validation leads to a generic XSS vector in the language override feature.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-55435

Publication date:
07/07/2026
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridgedserver`, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended user's unexpired token keeps working. Practical impact is limited to already-issued API keys of suspended users until those keys are deleted. Versions 2.32.7, 2.33.8, and 2.34.2 patch the issue. As a workaround, on suspension, delete the user's API keys via `DELETE /api/v2/users/{user}/keys`.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2026-48958

Publication date:
07/07/2026
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-48957

Publication date:
07/07/2026
An improper access check allows unauthorized users to access com_privacy datasets.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-48956

Publication date:
07/07/2026
An improper access check allows users to display a list of modules in the frontend.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-48955

Publication date:
07/07/2026
An improper access check allows unauthorized users to access workflow stage and transition information.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-48953

Publication date:
07/07/2026
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-48952

Publication date:
07/07/2026
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-48951

Publication date:
07/07/2026
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-48950

Publication date:
07/07/2026
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026