Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-82053

Publication date:
08/09/2026
A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication identities after user authentication under certain configurations. Subsequent authorization queries may execute under an unintended LDAP identity rather than the expected one. This can result in incorrect role assignments based on the LDAP directory's access control configuration, potentially allowing an authenticated user to acquire elevated privileges that were not intended by the deployment's authorization policy.
Severity CVSS v4.0: HIGH
Last modification:
08/09/2026

CVE-2026-81531

Publication date:
08/09/2026
An information<br /> disclosure vulnerability has been identified in Omada Controller.  An API endpoint intended for Controller initialization<br /> remains accessible after completion and may disclose account-related<br /> information to unauthenticated remote users. <br /> <br /> <br /> <br /> <br /> <br /> <br /> Successful<br /> exploitation may allow an attacker to remote query the affected endpoint that<br /> may facilitate user enumeration and subsequent attacks targeting administrative<br /> accounts.
Severity CVSS v4.0: MEDIUM
Last modification:
21/09/2026

CVE-2026-82052

Publication date:
08/09/2026
The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a MongoDB server (mongod). Under certain specific conditions the  regex match can start in the middle of a multi-code-unit character, triggering an assertion during query execution.
Severity CVSS v4.0: HIGH
Last modification:
08/09/2026

CVE-2026-79569

Publication date:
08/09/2026
Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2026

CVE-2026-78997

Publication date:
08/09/2026
UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL on a UC-owned domain (via a reflected XSS) that leverages the browser&amp;#39;s internal JavaScript bridge to register a deferred callback, navigate the tab to a victim site, and then execute attacker-controlled code on that site when a login dialog is dismissed.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2026

CVE-2026-79570

Publication date:
08/09/2026
mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2026

CVE-2026-75156

Publication date:
08/09/2026
Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because the signing keys are fetched from Microsoft&amp;#39;s **multi-tenant** JWKS endpoint, an `id_token` minted in *any* Azure tenant — including one the attacker creates — passes signature verification, and the username and role assignments are then read from that attacker-controlled token. Anyone able to register an Azure tenant can therefore authenticate to the Airflow UI with no prior access to the deployment.<br /> <br /> The fix for **CVE-2026-59243** was incomplete, and this advisory closes the remaining gap: that fix made the provider verify the `id_token` signature, but did not add issuer or audience checks. Operators who already applied the CVE-2026-59243 fix are **still affected and must upgrade again** — 3.7.3 is the release that shipped that fix, so every version containing it falls inside this affected range. Upgrade to apache-airflow-providers-fab `3.8.1` or later.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2026

CVE-2026-78216

Publication date:
08/09/2026
AshLua exposes Ash read actions to Lua scripts run through an eval action. A read call accepts an operation (list, min, max, first, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value.<br /> <br /> Ash field policies redact forbidden fields on returned records (replacing them with %Ash.ForbiddenField{}), but that redaction does not apply to aggregate values. A script could therefore read a field the calling actor&amp;#39;s field policies forbid by requesting it as an aggregate instead of as a field. This includes fields that are public? true but restricted per-actor by a field policy, such as sensitive PII. The prior hardening only enforced the exposed-field allow-list (field visibility), which is a separate axis from per-actor field-policy authorization.<br /> <br /> The fix authorizes the aggregated field against the resource&amp;#39;s field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible.<br /> <br /> This issue affects ash_lua: from 0.1.0 before 0.2.2.
Severity CVSS v4.0: MEDIUM
Last modification:
08/09/2026

CVE-2026-78230

Publication date:
08/09/2026
AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (min, max, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value.<br /> <br /> Ash field policies redact forbidden fields on returned records (replacing them with %Ash.ForbiddenField{}), but that redaction does not apply to aggregate values. A tool caller could therefore read a field the calling actor&amp;#39;s field policies forbid by requesting it as an aggregate; min/max in particular return an actual field value. This includes fields that are public? true but restricted per-actor by a field policy, such as sensitive PII. The tool&amp;#39;s existing check only required the field to be public, which is a separate axis from per-actor field-policy authorization.<br /> <br /> The fix authorizes the aggregated field against the resource&amp;#39;s field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible.<br /> <br /> This issue affects ash_ai: from 0.1.0 before 1.0.3.
Severity CVSS v4.0: MEDIUM
Last modification:
08/09/2026

CVE-2026-52307

Publication date:
08/09/2026
An authenticated stored cross-site scripting (XSS) vulnerability in the Column Management component of ClassCMS 1CMS v5.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the title field.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2026

CVE-2026-47625

Publication date:
08/09/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2026

CVE-2026-22575

Publication date:
08/09/2026
An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.4.1 through 7.4.10, FortiManager Cloud 7.2 all versions may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2026