Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-4767

Publication date:
02/07/2026
Missing authentication for critical function vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Authentication Abuse.<br /> <br /> This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117.
Severity CVSS v4.0: Pending analysis
Last modification:
02/07/2026

CVE-2026-5524

Publication date:
02/07/2026
The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. This is due to insufficient file extension validation in the do_image_upload() function where user-supplied input from the acceptFileTypes POST parameter is directly interpolated into a regular expression used to validate uploaded files. Attackers can specify PHP-executable extensions such as .phtml, .phar, .php5, or .php7 to bypass the plugin&amp;#39;s .htaccess protection which only blocks .php files specifically. Additionally, on Nginx-based servers, the .htaccess protection is completely ineffective as Nginx does not process .htaccess files. This makes it possible for unauthenticated attackers (who can obtain a nonce from any public page containing a form) to upload executable PHP files to the publicly accessible /wp-content/uploads/de_fb_uploads/ directory and achieve Remote Code Execution by accessing the uploaded file via HTTP. The vulnerability was partially patched in version 5.1.3.
Severity CVSS v4.0: Pending analysis
Last modification:
02/07/2026

CVE-2026-58652

Publication date:
02/07/2026
luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the luci-app-travelmate write ACL is granted config-wide UCI write access to the travelmate configuration. While the LuCI UI restricts the auto-login script picker to /etc/travelmate/*.login, this is only a frontend restriction. The backend travelmate service (running as root) reads the raw UCI &amp;#39;script&amp;#39; and &amp;#39;script_args&amp;#39; values and executes the configured path when the captive-portal auto-login branch (f_check() in travelmate-functions.sh) is reached. An attacker with delegated write permissions can set script to /bin/sh and script_args to attacker-controlled arguments, resulting in arbitrary command execution as root. Confirmed in luci-app-travelmate/travelmate 2.4.5-r3; the sink is still present in travelmate 2.4.6-1 and no patched version is known.
Severity CVSS v4.0: HIGH
Last modification:
02/07/2026

CVE-2026-58653

Publication date:
02/07/2026
PraisonAI before 0.1.7 fails to validate that project_id in issue create and update request bodies belongs to the URL workspace. An attacker can create issues referencing projects from other workspaces, causing cross-tenant data pollution in project statistics aggregation without workspace constraints.
Severity CVSS v4.0: MEDIUM
Last modification:
02/07/2026

CVE-2026-4770

Publication date:
02/07/2026
Improper neutralization of input during web page generation (&amp;#39;cross-site scripting&amp;#39;) vulnerability in TR7 Cyber ​​Defense Inc. Web Application Firewall allows DOM-Based XSS.<br /> <br /> This issue affects Web Application Firewall: from v1.0.42.239 before v1.4.0.117.
Severity CVSS v4.0: Pending analysis
Last modification:
02/07/2026

CVE-2026-4772

Publication date:
02/07/2026
Improper neutralization of input during web page generation (&amp;#39;cross-site scripting&amp;#39;) vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Stored XSS.<br /> <br /> This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117.
Severity CVSS v4.0: Pending analysis
Last modification:
02/07/2026

CVE-2026-57765

Publication date:
02/07/2026
Contributor SQL Injection in WP EasyCart
Severity CVSS v4.0: Pending analysis
Last modification:
02/07/2026

CVE-2026-57766

Publication date:
02/07/2026
Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager &amp; Code Editor
Severity CVSS v4.0: Pending analysis
Last modification:
02/07/2026

CVE-2026-57760

Publication date:
02/07/2026
Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels.<br /> <br /> This issue affects Sendcloud Shipping: from n/a through 1.0.29.
Severity CVSS v4.0: Pending analysis
Last modification:
02/07/2026

CVE-2026-57762

Publication date:
02/07/2026
Author Cross Site Scripting (XSS) in Simple URLs
Severity CVSS v4.0: Pending analysis
Last modification:
02/07/2026

CVE-2026-57763

Publication date:
02/07/2026
Contributor Cross Site Scripting (XSS) in Structured Content
Severity CVSS v4.0: Pending analysis
Last modification:
02/07/2026

CVE-2026-57764

Publication date:
02/07/2026
Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode
Severity CVSS v4.0: Pending analysis
Last modification:
02/07/2026