Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-19203

Publication date:
08/09/2026
A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling.<br /> <br /> <br /> <br /> <br /> This is caused by Jetty accepting a lone LF character as a terminator in parts of chunked request parsing. Depending on the Jetty version and configured HTTP compliance mode, this may occur in chunk extensions, chunk data termination, or trailer termination.
Severity CVSS v4.0: HIGH
Last modification:
08/09/2026

CVE-2026-11573

Publication date:
08/09/2026
Uncontrolled recursion in Qt&amp;#39;s QDomDocument serialization (QtXml) lets deeply nested untrusted XML crash the app via stack exhaustion (DoS only).
Severity CVSS v4.0: HIGH
Last modification:
08/09/2026

CVE-2026-12611

Publication date:
08/09/2026
A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive.<br /> <br /> <br /> <br /> <br /> This is caused by a race condition in the server when handling RST_STREAM frames and GOAWAY frames sent by the client.<br /> <br /> <br /> <br /> <br /> The race condition "resets" the HTTP2Flusher.terminated, previously set to a non-null value, to the null value, allowing entries to be enqueued in the flusher that however will never be processed. These unprocessed entries are the ones that would unblock the write-blocked threads.
Severity CVSS v4.0: HIGH
Last modification:
08/09/2026

CVE-2026-86713

Publication date:
08/09/2026
PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in the load_mon module&amp;#39;s stop path where exit_and_cleanup() deletes the LoadMon object and frees the performance counter before perf_end() attempts to access it. Attackers can trigger this vulnerability by issuing the load_mon stop command from any PXH or MAVLink shell, causing reads and writes through freed memory that corrupt heap objects and destabilize the flight stack.
Severity CVSS v4.0: HIGH
Last modification:
08/09/2026

CVE-2026-86714

Publication date:
08/09/2026
PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply interface names of 74 bytes or more via the -i option to read beyond buffer boundaries, leaking stack memory to console output or writing it into persistent network configuration files.
Severity CVSS v4.0: MEDIUM
Last modification:
08/09/2026

CVE-2026-80219

Publication date:
08/09/2026
Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.
Severity CVSS v4.0: Pending analysis
Last modification:
21/09/2026

CVE-2026-76931

Publication date:
08/09/2026
The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 3.3.205 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability can only be exploited when the &amp;#39;Directly link to project&amp;#39; plugin setting is disabled.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2026

CVE-2026-77968

Publication date:
08/09/2026
A flaw was found in hawtio-operator. The operator&amp;#39;s ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the ServiceAccount token authorizes read access to every Secret in the cluster. The operator also bypasses the cache via direct API calls. Compromise of the operator pod would yield read access to every Secret in the cluster, including bootstrap tokens, cloud credentials, and other operators&amp;#39; secrets.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2026

CVE-2026-78234

Publication date:
08/09/2026
A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource. Because the operator ships a ClusterRole that aggregates Hawtio CR permissions into the edit and admin roles, any user with edit access in any namespace can obtain a Service-CA-signed certificate with an arbitrary subject. This certificate can be used to impersonate any in-cluster service identity to peers that trust the Service CA for client authentication, including Jolokia agents and other Service-CA-trusting components.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2026

CVE-2026-86711

Publication date:
08/09/2026
electerm before 5.3.15 exposes 40+ main-process functions through an unvalidated Electron IPC handler with no function-name allowlist or sender validation. Renderer-side script execution can invoke openFileWithEditor and other functions with arbitrary arguments to execute system commands in the main process.
Severity CVSS v4.0: HIGH
Last modification:
08/09/2026

CVE-2026-86712

Publication date:
08/09/2026
SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled desktop renderer. Attackers can craft malicious web pages that write to the clipboard, and when pasted into SiYuan, injected scripts execute with full Node.js access through the Electron main process.
Severity CVSS v4.0: HIGH
Last modification:
08/09/2026

CVE-2026-74860

Publication date:
08/09/2026
A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.
Severity CVSS v4.0: Pending analysis
Last modification:
28/09/2026