Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-69399

Publication date:
17/09/2026
Azure Arc Elevation of Privilege Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
25/09/2026

CVE-2026-68791

Publication date:
17/09/2026
Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.
Severity CVSS v4.0: Pending analysis
Last modification:
25/09/2026

CVE-2026-55946

Publication date:
17/09/2026
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
Severity CVSS v4.0: Pending analysis
Last modification:
25/09/2026

CVE-2026-93426

Publication date:
17/09/2026
SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names to break out of identifiers and string literals, executing arbitrary ClickHouse SQL to read system tables and exfiltrate data.
Severity CVSS v4.0: HIGH
Last modification:
22/09/2026

CVE-2026-93307

Publication date:
17/09/2026
A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Collector. Such manipulation of the argument additionalFields.padding leads to uncontrolled memory allocation. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through a bug report but has not responded yet.
Severity CVSS v4.0: LOW
Last modification:
23/09/2026

CVE-2026-73638

Publication date:
17/09/2026
Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd.<br /> <br /> tiff_load_ifd() validates an IFD entry&amp;#39;s data by checking that `entry-&gt;offset + entry-&gt;size` stays within the EXIF block, and never checks the start offset itself. Where that sum is not the real end of the data, the check passes with the entry starting outside the block.<br /> <br /> Through 1.032 `entry-&gt;offset` is a plain int, so on the usual two&amp;#39;s-complement implementations an offset with the high bit set converts to negative and the sum can land back inside the block. From 1.033 the field is a size_t and the addition wraps only where size_t is 32 bits. The IFD&amp;#39;s own start offset is checked the same way and wraps where unsigned long is 32 bits, which includes 64-bit Windows.<br /> <br /> Any caller of Imager-&gt;read() on an attacker-supplied image may receive EXIF tags holding bytes from outside the block, or crash the process.
Severity CVSS v4.0: Pending analysis
Last modification:
22/09/2026

CVE-2026-73639

Publication date:
17/09/2026
Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8.<br /> <br /> With a tRNS chunk, read_direct8() adds an alpha channel to the image it creates but still sizes the row buffer from the original channel count. libpng expands the transparency into that extra channel, so png_read_row() fills one channel more than the buffer holds, at one byte per sample, and writes width bytes past the end of the allocation. Palette images go to read_paletted() and 16-bit images to read_direct16(), which sizes its buffer from png_get_rowbytes() and allocates enough for the expanded row.<br /> <br /> The same reader ships bundled in the Imager distribution.<br /> <br /> Reading an attacker-supplied PNG through Imager-&gt;read() corrupts the heap, which can crash the process.
Severity CVSS v4.0: Pending analysis
Last modification:
22/09/2026

CVE-2026-54734

Publication date:
17/09/2026
Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious actor who can supply bid-request parameters can cause the server to send HTTP requests to unintended destinations, potentially reaching internal network services, metadata endpoints, or other sensitive server endpoints with the server&amp;#39;s network access. This issue is fixed in version 3.43.0.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-54647

Publication date:
17/09/2026
CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates the administrator-controlled download_expire POST parameter into a raw UPDATE statement for CubeCart_downloads without numeric validation. An authenticated administrator can supply a comma-delimited value that changes the SET clause because HTML sanitization does not neutralize SQL syntax, allowing manipulation of database columns and potentially other data within the application&amp;#39;s database privileges. This issue is fixed in version 6.7.5.
Severity CVSS v4.0: Pending analysis
Last modification:
24/09/2026

CVE-2026-54645

Publication date:
17/09/2026
CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, description_short, and spec_copy rich-text fields from $GLOBALS[&amp;#39;RAW&amp;#39;][&amp;#39;POST&amp;#39;] and removes only script elements before the values are stored and rendered through Smarty templates. An administrator with product-editing rights can store event-handler attributes, SVG content, or javascript: URIs that bypass this filter, causing persistent JavaScript execution when a storefront visitor or another administrator views the product content and enabling session exposure or unauthorized browser-context actions. This issue is fixed in version 6.7.5.
Severity CVSS v4.0: Pending analysis
Last modification:
24/09/2026

CVE-2026-54643

Publication date:
17/09/2026
CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete-note handler in admin/sources/orders.index.inc.php verifies only the presence of order_id and delete-note parameters before deleting records from CubeCart_order_notes, without requiring CC_PERM_DELETE for orders. An authenticated administrator lacking order modification privileges can directly invoke the handler with valid identifiers and delete order-history notes, removing operational records and audit-trail data. This issue is fixed in version 6.7.5.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-54646

Publication date:
17/09/2026
CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled tablename values into ALTER TABLE, CHECK TABLE, and ANALYZE TABLE statements without validating the identifiers or escaping embedded backticks. An authenticated administrator can terminate the quoted identifier with a closing backtick and introduce attacker-controlled structural SQL, potentially compromising database confidentiality, integrity, and availability within the application&amp;#39;s database privileges. This issue is fixed in version 6.7.5.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026