Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-9501

Publication date:
25/05/2026
A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. Executing a manipulation can lead to reachable assertion. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. This patch is called e501cb9926c1e9a07a0d1cc997f3e69e9be801c9. A patch should be applied to remediate this issue.
Severity CVSS v4.0: LOW
Last modification:
26/05/2026

CVE-2026-9502

Publication date:
25/05/2026
A vulnerability was identified in GNU LibreDWG up to 0.14. This affects the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is e501cb9926c1e9a07a0d1cc997f3e69e9be801c9. To fix this issue, it is recommended to deploy a patch.
Severity CVSS v4.0: LOW
Last modification:
26/05/2026

CVE-2026-48852

Publication date:
25/05/2026
PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2026

CVE-2026-48851

Publication date:
25/05/2026
PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2026

CVE-2026-48850

Publication date:
25/05/2026
PuTTY 0.72 before 0.84 has a double free in RSA KEX.
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2026

CVE-2026-48589

Publication date:
25/05/2026
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login.<br /> In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the Jakarta EE module.<br /> This issue affects Apache Shiro from 2.0-alpha to 2.2.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration module.
Severity CVSS v4.0: NONE
Last modification:
28/05/2026

CVE-2026-24545

Publication date:
25/05/2026
Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Control Security Levels.<br /> <br /> This issue affects QR Redirector: from n/a through 2.0.3.
Severity CVSS v4.0: Pending analysis
Last modification:
26/05/2026

CVE-2026-24574

Publication date:
25/05/2026
Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows Cross Site Request Forgery.<br /> <br /> This issue affects Export WP Page to Static HTML/CSS: from n/a through 6.0.0.
Severity CVSS v4.0: Pending analysis
Last modification:
26/05/2026

CVE-2026-24597

Publication date:
25/05/2026
Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart allows Cross Site Request Forgery.<br /> <br /> This issue affects Organization chart: from n/a through 1.7.5.
Severity CVSS v4.0: Pending analysis
Last modification:
26/05/2026

CVE-2026-44598

Publication date:
25/05/2026
With valid login credentials, URL Redirection to Untrusted Site (&amp;#39;Open Redirect&amp;#39;), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro.<br /> <br /> <br /> <br /> <br /> This issue affects Apache Shiro from 2.0-alpha to 2.1.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration module.<br /> <br /> Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue by encrypting the cookie.<br /> <br /> After successful login, Jakarta EE integration module uses shiroSavedRequest cookie to redirect to a particular web page after login.<br /> This cookie was not validated, and can be forged to send a HTTP GET request from the server itself to an arbitrary URL from the cookie.
Severity CVSS v4.0: MEDIUM
Last modification:
28/05/2026

CVE-2026-43828

Publication date:
25/05/2026
Default configurations of Apache Shiro send sensitive cookies in HTTPS session without &amp;#39;Secure&amp;#39; attribute.<br /> <br /> <br /> <br /> This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1.<br /> <br /> Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue.<br /> <br /> In the affected versions, Shiro-native session manager, as well as Remember-Me manager sends JSESSIONID and rememberMe cookies without &amp;#39;secure&amp;#39; attribute by default.
Severity CVSS v4.0: MEDIUM
Last modification:
28/05/2026

CVE-2026-43827

Publication date:
25/05/2026
Default configurations of Apache Shiro have a session fixation vulnerability.<br /> <br /> This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1.<br /> <br /> Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue.<br /> <br /> In the affected versions, when a session already exists, it is not invalidated upon successful login, nor is a new session being generated with a new ID.
Severity CVSS v4.0: MEDIUM
Last modification:
28/05/2026