Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-92400

Publication date:
21/09/2026
The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account before marking an order complete, allowing unauthenticated users to mark their own orders as paid using a genuine transaction from a payment sandbox they control.
Severity CVSS v4.0: Pending analysis
Last modification:
22/09/2026

CVE-2026-94152

Publication date:
21/09/2026
A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an unknown function of the file /user/ of the component User Profile API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity CVSS v4.0: LOW
Last modification:
22/09/2026

CVE-2026-85010

Publication date:
21/09/2026
The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-chosen total, down to and including zero.
Severity CVSS v4.0: Pending analysis
Last modification:
21/09/2026

CVE-2026-15801

Publication date:
21/09/2026
A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers from checkpoint archives, insufficient validation of restore metadata may allow a user with sufficient privileges to perform unintended operations on the host filesystem. Successful exploitation requires that container checkpoint and restore functionality is enabled, which is not the default configuration. An attacker must also be able to trigger restoration of a container from untrusted checkpoint content.
Severity CVSS v4.0: Pending analysis
Last modification:
22/09/2026

CVE-2025-12999

Publication date:
21/09/2026
UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with no check on whether the sender was a trusted proxy, falling back to the client-supplied Host header. <br /> <br /> <br /> <br /> <br /> Those responses are cached under keys that do not include the host (extension.json since 0.6.0, namespace.details.json since 0.9.0, sitemap since 0.14.5, latest.extension.version.vscode since 0.34.2). A single request carrying a forged header therefore places attacker-chosen URLs into an entry served to every other client for the lifetime of that entry — one hour by default, and cluster-wide where ovsx.redis.enabled is set.<br /> <br /> <br /> <br /> The VSIX download URL, its signature URL and the public key URL are all derived from the same base URL, so extension signing does not limit the impact: an attacker who poisons an entry supplies the package, the signature over it, and the key used to verify it. <br /> <br /> <br /> <br /> Exploitability depends on deployment topology. A server reachable directly by clients, or fronted by a proxy that relays the client&amp;#39;s X-Forwarded-Host rather than overwriting it, is exploitable by an unauthenticated remote attacker. A proxy that overwrites the header is not.<br /> <br /> <br /> <br /> An unauthenticated attacker can poison Open VSX&amp;#39;s per-extension metadata cache with attacker-controlled download, signature, and public-key URLs by supplying a crafted X-Forwarded-Host header, causing downstream VS Code-compatible editors to fetch and install a malicious VSIX.<br /> <br /> <br /> <br /> Workarounds (unpatched versions)<br /> <br /> <br /> <br /> <br /> 1. Configure the reverse proxy to set rather than relay X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix — note that nginx&amp;#39;s $host is the client&amp;#39;s Host header and is not a safe value.<br /> <br /> <br /> <br /> 2. Ensure the server is not reachable except through that proxy.<br /> <br /> <br /> <br /> 3. Flush the caches afterwards; poisoned entries survive the configuration change.
Severity CVSS v4.0: CRITICAL
Last modification:
22/09/2026

CVE-2026-94149

Publication date:
21/09/2026
A vulnerability was identified in Omega Solution HRM OS up to 20260717. The affected element is an unknown function of the file /role-permission/permission of the component Role Permission Retrieval Endpoint. Such manipulation of the argument roleId leads to improper control of resource identifiers. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity CVSS v4.0: LOW
Last modification:
21/09/2026

CVE-2026-94148

Publication date:
21/09/2026
A vulnerability was determined in ScadaBR up to 1.1. Impacted is the function EmportDwr.createExportJSON of the file /ScadaBR/export_project.htm of the component Export Project Endpoint. This manipulation causes information disclosure. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.2.0 is recommended to address this issue. Patch name: c852b4988a15bce6011ef169299ad604538f70a9. The affected component should be upgraded. Import path was already gated with Permissions.ensureAdmin(); only export was left unprotected.
Severity CVSS v4.0: MEDIUM
Last modification:
21/09/2026

CVE-2026-47321

Publication date:
21/09/2026
The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not control the resulting size, and create a buffer no matter what.<br /> <br /> Some compressed data may have a compression ration greater than 1 thousand, leading to an exhaustion of the application memory, as we don&amp;#39;t control the deflated size.<br /> <br /> <br /> <br /> <br /> The fix adds such a control by allowing the application developer to provide a fixed size limit, which when reached throws an exception. It also allows the user to provide a compression ratio that should not be exceeded, protected the application from small inflated files that inflate in gigantic files, but with a grace limit for the resulting size (1Mb) to avoid false positive (like a very small file inflating with a high ratio, but resulting with a acceptable size, like a few thousands bytes)<br /> <br /> <br /> <br /> <br /> For application using this feature, it is highly recommended to create the CompressionFilter and to pass the maximum limit as a forth constructor parameter, maxDecompressedSize:<br /> <br /> <br /> <br /> <br /> public CompressionFilter(final boolean compressInbound, final boolean compressOutbound, final int compressionLevel, final int maxDecompressedSize)Optionally one can also provide a maxDecompressRatio fifth parameter, and a decompressRatioMinSize sixth parameter to allow small inflated files with a high compression ratio to still be accepted.<br /> <br /> <br /> <br /> <br /> Here are the additional constructor:<br /> <br /> <br /> <br /> <br /> <br /> <br /> public CompressionFilter(final boolean compressInbound, final boolean compressOutbound,<br /> <br /> <br /> <br /> final int compressionLevel, final int maxDecompressedSize,<br /> <br /> <br /> <br /> final long maxDecompressRatio, final long decompressRatioMinSize)<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> Also note that a fluent API has been added to spare the users the pain to call a constructor with that many parameters:<br /> <br /> <br /> <br /> <br /> <br /> <br />  CompressionFilter compressionFilter = new CompressionFilter()<br /> <br />     .setCompressionLevel(Zlib.COMPRESSION_MAX)<br /> <br />   .setMaxDecompressedSize(1_000_000)<br /> <br />   .setMaxDecompressRatio(100).<br /> <br />   .setDecompressRatioMinSize(100_000); <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> Applications using Apache MINA are advised to upgrade and configure their CompressionFilter instance.
Severity CVSS v4.0: Pending analysis
Last modification:
21/09/2026

CVE-2026-94217

Publication date:
21/09/2026
A flaw was found in the User-Managed Access (UMA) implementation of Keycloak. The issue occurs in the authorization token endpoint when processing permission tickets. If two different users own resources with the same name, the system incorrectly merges the permissions from both resources when one user requests an authorization token. This allows an attacker to gain access scopes on a victim&amp;#39;s resource that were never intended to be shared.
Severity CVSS v4.0: Pending analysis
Last modification:
24/09/2026

CVE-2026-94213

Publication date:
21/09/2026
A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution. The issue occurs in the policy evaluation endpoint, which is used by administrators to test how access policies apply to specific users. Due to missing authorization checks, a delegated administrator with limited viewing privileges can access the full profile and role information of any user in the realm, even if they are not permitted to view user details. This could lead to the exposure of sensitive information such as email addresses and assigned security roles.
Severity CVSS v4.0: Pending analysis
Last modification:
22/09/2026

CVE-2026-94215

Publication date:
21/09/2026
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs because the API uses a per-request in-memory cache to resolve clients by their unique identifier without verifying if the client belongs to the realm specified in the request path. This allows an administrator with limited privileges to read or modify sensitive client configurations in the master realm by accessing them through a realm they control. Successful exploitation could lead to the exposure of client credentials or the redirection of administrative login attempts to malicious sites.
Severity CVSS v4.0: Pending analysis
Last modification:
22/09/2026

CVE-2026-94218

Publication date:
21/09/2026
A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The issue occurs when an administrator enforces a stronger authentication flow, such as mandatory two-factor authentication (2FA) setup, through a client policy. A user can bypass this requirement by manually visiting a specific session restart web link during the login process. This action clears the internal markers that track the required security steps, allowing the user to log in with only a password and gain access without completing the mandated 2FA setup.
Severity CVSS v4.0: Pending analysis
Last modification:
22/09/2026