Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-66279

Publication date:
10/06/2026
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands.<br /> <br /> We have already fixed the vulnerability in the following versions:<br /> QTS 5.2.9.3410 build 20260214 and later<br /> QuTS hero h5.2.9.3410 build 20260214 and later<br /> QuTS hero h5.3.4.3500 build 20260520 and later<br /> QuTS hero h6.0.0.3397 build 20260206 and later
Severity CVSS v4.0: HIGH
Last modification:
23/07/2026

CVE-2025-66280

Publication date:
10/06/2026
An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to compromise the security of the system.<br /> <br /> We have already fixed the vulnerability in the following versions:<br /> QTS 5.2.9.3410 build 20260214 and later<br /> QuTS hero h5.2.9.3410 build 20260214 and later<br /> QuTS hero h5.3.4.3500 build 20260520 and later<br /> QuTS hero h6.0.0.3397 build 20260206 and later
Severity CVSS v4.0: MEDIUM
Last modification:
23/07/2026

CVE-2025-62851

Publication date:
10/06/2026
A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data.<br /> <br /> We have already fixed the vulnerability in the following version:<br /> License Center 1.9.56 and later
Severity CVSS v4.0: MEDIUM
Last modification:
23/07/2026

CVE-2025-62850

Publication date:
10/06/2026
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.<br /> <br /> We have already fixed the vulnerability in the following versions:<br /> QuTS hero h5.2.9.3410 build 20260214 and later<br /> QuTS hero h5.3.4.3500 build 20260520 and later<br /> QuTS hero h6.0.0.3459 build 20260409 and later
Severity CVSS v4.0: MEDIUM
Last modification:
23/07/2026

CVE-2025-58468

Publication date:
10/06/2026
A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities.<br /> <br /> We have already fixed the vulnerability in the following version:<br /> Notification Center 1.10.0.3291 and later
Severity CVSS v4.0: MEDIUM
Last modification:
23/07/2026

CVE-2025-59382

Publication date:
10/06/2026
QTS, QuTS hero, QuTScloud are not affected.<br /> <br /> We have already fixed the vulnerability in the following version:
Severity CVSS v4.0: LOW
Last modification:
23/07/2026

CVE-2025-66276

Publication date:
10/06/2026
QuTS hero is not affected.<br /> <br /> We have already fixed the vulnerability in the following version:<br /> QTS 5.2.7.3256 build 20250913 and later
Severity CVSS v4.0: CRITICAL
Last modification:
23/07/2026

CVE-2026-45542

Publication date:
10/06/2026
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a heap buffer overflow exists in the Security Scheme 2 (SRP6a) session-setup path of the protocomm component. The first-phase handler (handle_session_command0() in components/protocomm/src/security/security2.c) trusts the length of a client-supplied protobuf field for the SRP6a username and copies it into a buffer whose size is derived from a narrower destination type. The resulting truncation-versus-copy asymmetry corrupts the heap when an oversized value is supplied. This issue has been patched in versions 5.2.7, 5.3.6, 5.4.5, 5.5.5, and 6.0.1.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-46532

Publication date:
10/06/2026
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0, an out-of-bounds read exists in the BlueDroid AVRCP vendor-command parser (avrc_pars_vendor_cmd() in components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c). This issue has been patched in versions 5.2.7, 5.3.6, 5.4.5, 5.5.4, and 6.0.1.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-45160

Publication date:
10/06/2026
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0.1, an out-of-bounds read flaw exists in the DHCP server option parser (parse_options() in components/lwip/apps/dhcpserver/dhcpserver.c) shipped with ESP-IDF&amp;#39;s lwIP component. The parser walks the BOOTP/DHCP options field without validating that each option&amp;#39;s length byte and declared payload length stay within the received packet buffer. A crafted DHCP request can cause the parser to read past the end of the options buffer into adjacent heap memory. The issue affects the DHCP server used by ESP-IDF&amp;#39;s SoftAP and any configuration where the device runs as a DHCP server on a local network. This issue has been patched in versions 5.2.8, 5.3.6, 5.4.5, 5.5.5, and 6.0.2.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-45328

Publication date:
10/06/2026
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c that bridge calls from the user application (i.e. the REE) to TEE-protected hardware peripherals (AES, SHA, ECC, HMAC, SPI, MMU, WDT) and to the security feature like attestation, OTA updates, secure storage. This issue has been patched in versions 5.5.5 and 6.0.1.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026

CVE-2026-45329

Publication date:
10/06/2026
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c validated only some of the caller-supplied pointer arguments, leaving input pointer arguments unchecked. Because the underlying TEE-protected hardware peripherals (e.g., ECC, SHA, SPI) run in RISC-V machine mode (M-mode) with full address-space access, a caller could supply pointers into TEE-exclusive memory as inputs, causing the peripheral to read TEE memory and return results derived from it to the REE. Depending on the wrapper, the result contains raw bytes from TEE memory, a computed function of TEE memory recoverable through repeated calls, or a single bit per call that forms an oracle for incremental disclosure of TEE-resident sensitive data. This issue has been patched in versions 5.5.5 and 6.0.1.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2026