Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-21760

Publication date:
17/07/2026
HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access restricted administrative functionality by directly accessing protected application endpoints.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2026-21761

Publication date:
17/07/2026
HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentially exposing application resources to untrusted domains.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2026-16108

Publication date:
17/07/2026
A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated administrator with realm-viewing permissions to see the names and identifiers of hidden default groups, even if they lack the specific permissions to view those groups. This can lead to the exposure of sensitive organizational structures or internal group names.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2026

CVE-2026-16106

Publication date:
17/07/2026
A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks, an attacker with limited administrative permissions can remove privileged roles they are not authorized to manage, leading to a loss of access for other users and administrators.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2026

CVE-2026-16104

Publication date:
17/07/2026
A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive configuration values, such as reCAPTCHA secret keys, when they are requested by administrators with view-only permissions. This can lead to the exposure of third-party service credentials to unauthorized personnel or through administrative logs.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2026

CVE-2026-16103

Publication date:
17/07/2026
A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler but were omitted from the token redemption handler. This allows an attacker with valid client credentials to obtain access and refresh tokens for a user account that has been locked due to brute-force protection, provided the authentication request was started before the lockout occurred and was approved by the user.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2026

CVE-2026-16093

Publication date:
17/07/2026
Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that tricks the system into thinking the policy requirements have been met. This allows the attacker to authenticate using simpler methods like a client secret even when the administrator has mandated more secure, signed assertions.
Severity CVSS v4.0: Pending analysis
Last modification:
09/08/2026

CVE-2026-11763

Publication date:
17/07/2026
Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&amp;D and Software Services Inc. GisLab Laboratory Management System allows Exploitation of Trusted Identifiers.<br /> <br /> This issue affects GisLab Laboratory Management System: from 1.4.03 through 08072026.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2026-12691

Publication date:
17/07/2026
Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass.<br /> <br /> This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2026-12692

Publication date:
17/07/2026
Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass.<br /> <br /> This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2026-12693

Publication date:
17/07/2026
Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs.<br /> <br /> This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2026-12694

Publication date:
17/07/2026
Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs.<br /> <br /> This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026