Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-48953

Publication date:
07/07/2026
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-48952

Publication date:
07/07/2026
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-48951

Publication date:
07/07/2026
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-48950

Publication date:
07/07/2026
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-48949

Publication date:
07/07/2026
Lack of validation leads to an XSS vulnerability in the MFA management views.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-48948

Publication date:
07/07/2026
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-48947

Publication date:
07/07/2026
An improper access check allows privileged users to overwrite media files without editing permissions.
Severity CVSS v4.0: MEDIUM
Last modification:
09/07/2026

CVE-2026-23698

Publication date:
07/07/2026
Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by submitting a crafted zip archive through the ModuleManager import function, which extracts contents directly into the modules/ directory under the web root without validating file types beyond the manifest.xml descriptor. Attackers can place executable PHP files in the modules/ directory that become directly accessible via HTTP, bypassing Vtiger's authentication and authorization layer entirely since Apache resolves the path and invokes the PHP interpreter before the application routing layer is involved, resulting in a persistent web shell independent of the originating session.
Severity CVSS v4.0: HIGH
Last modification:
08/07/2026

CVE-2026-57851

Publication date:
07/07/2026
MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without administrator privileges. Attackers can exploit the accessible device object through IOCTL handlers to manipulate kernel objects, tamper with kernel-mode callbacks, bypass Protected Process Light protections, and disable security software.
Severity CVSS v4.0: HIGH
Last modification:
10/07/2026

CVE-2026-23697

Publication date:
07/07/2026
Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents module, bypassing the extension denylist in config.inc.php which omits the .phar extension. The uploaded file is stored with its original .phar extension under the web-accessible storage directory, and a misconfigured .htaccess using Apache 2.2 syntax is silently ignored on Apache 2.4 deployments, allowing unauthenticated HTTP requests to directly execute the uploaded PHP payload.
Severity CVSS v4.0: HIGH
Last modification:
08/07/2026

CVE-2026-14904

Publication date:
07/07/2026
AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS.<br /> <br /> <br /> <br /> Improper link resolution before file access issue (CWE-59) in the Auth.GetUserPrivateKey API. An authenticated remote user could read arbitrary files on the cluster-manager EC2 instance by replacing their SSH private key file (~/.ssh/id_rsa) with a symbolic link targeting any file on the host. Because the cluster-manager process runs as root, any file readable by root is exposed, including other users&amp;#39; SSH private keys and application configuration secrets.<br /> <br /> <br /> <br /> It&amp;#39;s recommended to upgrade to RES version 2026.06.
Severity CVSS v4.0: HIGH
Last modification:
08/07/2026

CVE-2026-13020

Publication date:
07/07/2026
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026