Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-81474

Publication date:
17/09/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
01/10/2026

CVE-2026-81439

Publication date:
17/09/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
Severity CVSS v4.0: Pending analysis
Last modification:
01/10/2026

CVE-2026-81438

Publication date:
17/09/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Severity CVSS v4.0: Pending analysis
Last modification:
01/10/2026

CVE-2026-66269

Publication date:
17/09/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
Severity CVSS v4.0: Pending analysis
Last modification:
06/10/2026

CVE-2026-78426

Publication date:
17/09/2026
The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.
Severity CVSS v4.0: LOW
Last modification:
28/09/2026

CVE-2026-78427

Publication date:
17/09/2026
The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any user capable of deploying workloads can evade admission deny rules simply by naming their image path after one of these sidecar images.
Severity CVSS v4.0: MEDIUM
Last modification:
28/09/2026

CVE-2026-78428

Publication date:
17/09/2026
For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
Severity CVSS v4.0: HIGH
Last modification:
28/09/2026

CVE-2026-78425

Publication date:
17/09/2026
Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SSO. The IdP issues an assertion to them. If that assertion is presented to NeuVector, NeuVector accepts it because the only thing distinguishing "an assertion for NeuVector" from "an assertion for the wiki" is the element, and the `NotInAudience` warning that reports the mismatch is never read.
Severity CVSS v4.0: HIGH
Last modification:
28/09/2026

CVE-2026-87963

Publication date:
17/09/2026
The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escaping, allowing unauthenticated attackers to perform SQL injection and read arbitrary database contents including administrator password hashes.
Severity CVSS v4.0: Pending analysis
Last modification:
20/09/2026

CVE-2026-44940

Publication date:
17/09/2026
The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unauthorized access or escalate privileges within the observability environment.
Severity CVSS v4.0: Pending analysis
Last modification:
29/09/2026

CVE-2026-25281

Publication date:
17/09/2026
Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.
Severity CVSS v4.0: Pending analysis
Last modification:
22/09/2026

CVE-2026-25282

Publication date:
17/09/2026
Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.
Severity CVSS v4.0: Pending analysis
Last modification:
22/09/2026