Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-44106

Publication date:
30/07/2026
A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
Severity CVSS v4.0: HIGH
Last modification:
30/07/2026

CVE-2026-44107

Publication date:
30/07/2026
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.
Severity CVSS v4.0: HIGH
Last modification:
30/07/2026

CVE-2026-44108

Publication date:
30/07/2026
Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise.
Severity CVSS v4.0: CRITICAL
Last modification:
30/07/2026

CVE-2026-7849

Publication date:
30/07/2026
Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.
Severity CVSS v4.0: CRITICAL
Last modification:
30/07/2026

CVE-2026-44099

Publication date:
30/07/2026
A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
Severity CVSS v4.0: HIGH
Last modification:
30/07/2026

CVE-2026-44100

Publication date:
30/07/2026
The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.
Severity CVSS v4.0: HIGH
Last modification:
30/07/2026

CVE-2026-44101

Publication date:
30/07/2026
Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.
Severity CVSS v4.0: CRITICAL
Last modification:
30/07/2026

CVE-2026-44102

Publication date:
30/07/2026
An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible for a short period before it is deleted due to improper locking during the cleanup process.
Severity CVSS v4.0: MEDIUM
Last modification:
30/07/2026

CVE-2026-44103

Publication date:
30/07/2026
An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected device. This vulnerability could be used in chain with CVE-2026-44104.
Severity CVSS v4.0: MEDIUM
Last modification:
30/07/2026

CVE-2026-44104

Publication date:
30/07/2026
The firmware update process for the basemodule of the charging controller only validates the<br /> CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.
Severity CVSS v4.0: CRITICAL
Last modification:
30/07/2026

CVE-2026-44105

Publication date:
30/07/2026
The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user "user-app". Charging could be interrupted.
Severity CVSS v4.0: MEDIUM
Last modification:
30/07/2026

CVE-2026-44092

Publication date:
30/07/2026
An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.
Severity CVSS v4.0: HIGH
Last modification:
30/07/2026