Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-0487

Publication date:
14/07/2026
SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on confidentiality, integrity and availability of the system.
Severity CVSS v4.0: Pending analysis
Last modification:
20/07/2026

CVE-2026-15620

Publication date:
14/07/2026
A security vulnerability has been detected in mosaxiv clawlet up to 0.2.10. This affects the function tools.webFetch of the file tools/tool_web_fetch.go. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The reported GitHub issue was closed with the label "not planned".
Severity CVSS v4.0: LOW
Last modification:
14/07/2026

CVE-2026-15619

Publication date:
14/07/2026
A weakness has been identified in mosaxiv clawlet up to 0.2.10. The impacted element is the function web_fetch of the file tools/tool_web_fetch.go of the component IPv4 Handler. This manipulation of the argument url causes server-side request forgery. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The reported GitHub issue was closed with the label "not planned".
Severity CVSS v4.0: LOW
Last modification:
15/07/2026

CVE-2026-15618

Publication date:
14/07/2026
A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. The affected element is the function guardExecCommand of the file tools/tool_exec.go of the component exec Safety Guard. The manipulation results in protection mechanism failure. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The reported GitHub issue was closed with the label "not planned".
Severity CVSS v4.0: LOW
Last modification:
14/07/2026

CVE-2026-58486

Publication date:
13/07/2026
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, HedgeDoc was vulnerable to a YAML alias bomb due to unsafe processing of the note frontmatter. HedgeDoc parsed frontmatter with js-yaml.load (js-yaml v3) via @hedgedoc/meta-marked, which resolved YAML anchor aliases. A compact malicious payload could therefore expand into a huge object structure, consuming excessive CPU. This expansion ran on every request to the publish view (/s/) and, when placed under the opengraph key, the editor view (/). A ten-level alias bomb could block the single Node.js event loop for roughly 235 seconds per request, causing concurrent requests to hang or drop and rendering the instance unavailable (DoS). Because the note was stored in the database, the impact survived process restarts until the note was removed. toobusy-js did not reliably mitigate the worst cases, as the event loop was saturated before the middleware could respond. This issue was fixed in version 1.11.0.
Severity CVSS v4.0: HIGH
Last modification:
14/07/2026

CVE-2026-58489

Publication date:
13/07/2026
HedgeDoc is an open source, real-time collaborative markdown notes application. Prior to 1.11.0, the GitHub Gist export flow created an OAuth2  state  value but only checked that it was present rather than validating it against the value expected for the user's session. Because the state was not properly validated, an attacker could forge a callback URL containing their own valid GitHub OAuth code. When processing the callback, HedgeDoc used the victim's logged-in session to select which note to export, but the attacker's authorization code to determine which GitHub account received it. As a result, a logged-in victim who clicked a crafted link could export their own private, protected, or limited note directly into a Gist controlled by the attacker. This issue has been fixed in version 1.11.0.
Severity CVSS v4.0: MEDIUM
Last modification:
14/07/2026

CVE-2026-58101

Publication date:
13/07/2026
Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference.<br /> <br /> X509V3_EXT_d2i(ext) returns NULL when an extension&amp;#39;s DER value fails to parse. basicC, ia5string, and auth_att dereference its result without a NULL check. keyid_data also dereferences akid-&gt;keyid, which is NULL for an empty AKI SEQUENCE (DER 30 00) even when the parse succeeds.<br /> <br /> A caller invoking an affected helper on an extension from an untrusted certificate triggers a SIGSEGV that crashes the Perl process.
Severity CVSS v4.0: Pending analysis
Last modification:
14/07/2026

CVE-2026-58102

Publication date:
13/07/2026
Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts.<br /> <br /> When building the extension hash (via extensions(), extensions_by_long_name(), extensions_by_oid(), or has_extension_oid()), the code passes OBJ_obj2txt()&amp;#39;s return value as the hash-key length; because that value is the OID&amp;#39;s full text length rather than the bytes written to the fixed-size buffer (129 bytes), an OID whose text is longer than the 129-byte buffer causes a read past the allocation, exposing adjacent heap memory as the returned hash key. extensions_by_name() uses the static shortname path and is not affected.
Severity CVSS v4.0: Pending analysis
Last modification:
14/07/2026

CVE-2026-15607

Publication date:
13/07/2026
A vulnerability was detected in tanstack db up to 0.6.8. Affected by this vulnerability is the function select of the file src/query/compiler/select.ts of the component Alias Path Handler. The manipulation results in improperly controlled modification of object prototype attributes. The attack may be launched remotely. The exploit is now public and may be used. The patch is identified as ac09b1177a100eafa85cba3cd09dd1f53f933ded. A patch should be applied to remediate this issue.
Severity CVSS v4.0: LOW
Last modification:
15/07/2026

CVE-2026-57855

Publication date:
13/07/2026
Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php executes bucket commands (ls, upload, removefiles, rename, createfolder) without performing any ACL or role check. Any authenticated user, regardless of role, can perform all bucket operations on any named bucket, including buckets intended for admin use only.
Severity CVSS v4.0: HIGH
Last modification:
14/07/2026

CVE-2026-57856

Publication date:
13/07/2026
Cockpit CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php sanitizes the bucket name with preg_replace(&amp;#39;/[^a-zA-Z0-9-_\\.]/&amp;#39;,&amp;#39;&amp;#39;, $bucket), which permits &amp;#39;..&amp;#39; and &amp;#39;../&amp;#39; sequences. The sanitized value is interpolated into a Flysystem path as uploads://buckets/{bucket}. Flysystem&amp;#39;s WhitespacePathNormalizer resolves &amp;#39;buckets/..&amp;#39; to the empty string (the uploads storage root) without raising PathTraversalDetected because the &amp;#39;..&amp;#39; has a preceding component to consume. An authenticated low-privileged user can send a crafted request with a &amp;#39;../&amp;#39; bucket name to list, upload, and delete files across all buckets, including those belonging to other users or roles
Severity CVSS v4.0: HIGH
Last modification:
14/07/2026

CVE-2026-15605

Publication date:
13/07/2026
A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download in the library wandb/sdk/lib/hashutil.py of the component Artifact Integrity Validation. The manipulation leads to use of weak hash. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The pull request to fix this issue awaits acceptance.
Severity CVSS v4.0: LOW
Last modification:
14/07/2026