Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-63768

Publication date:
20/07/2026
cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows attackers to redirect users to arbitrary URLs by crafting malicious state parameters. Attackers can exploit the unsigned state parameter and onErrorReturnTo field to silently redirect visitors from the trusted domain to attacker-controlled URLs for phishing attacks.
Severity CVSS v4.0: MEDIUM
Last modification:
20/07/2026

CVE-2026-63730

Publication date:
20/07/2026
HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to make requests to arbitrary internal network destinations by supplying a caller-controlled URL to the webhook test endpoint. Attackers can bypass the insufficient hostname blacklist validation in the webhook handler to enumerate internal services, interact with internal containers, or access cloud instance metadata services including provider metadata endpoints.
Severity CVSS v4.0: MEDIUM
Last modification:
20/07/2026

CVE-2026-63108

Publication date:
20/07/2026
Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions inside parameter expansion defaults. The command parser in parse-command.ts replaces parameter expansions with opaque placeholders before extracting command substitutions, causing the containsDangerousSubstitution guard to miss nested payloads, which are then auto-approved based on the outer allowlisted command prefix and executed by the shell via execa, enabling arbitrary command execution.
Severity CVSS v4.0: HIGH
Last modification:
20/07/2026

CVE-2026-63771

Publication date:
20/07/2026
Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forwarded-Prefix HTTP header used in Set-Cookie path attributes. Attackers can exploit a misconfigured reverse proxy to downgrade SameSite protection and enable cross-origin authenticated requests, bypassing cookie security controls.
Severity CVSS v4.0: MEDIUM
Last modification:
20/07/2026

CVE-2026-63769

Publication date:
20/07/2026
Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe internal network services, enumerate ports via error signatures, and access cloud metadata endpoints to retrieve sensitive credentials.
Severity CVSS v4.0: MEDIUM
Last modification:
21/07/2026

CVE-2026-61900

Publication date:
20/07/2026
The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.
Severity CVSS v4.0: CRITICAL
Last modification:
20/07/2026

CVE-2026-61901

Publication date:
20/07/2026
The Joomla extension Hikashop is vulnerable to an open redirect.
Severity CVSS v4.0: Pending analysis
Last modification:
20/07/2026

CVE-2026-62414

Publication date:
20/07/2026
The Joomla extension Page Builder CK does not properly apply access control to frontend page list views.
Severity CVSS v4.0: Pending analysis
Last modification:
20/07/2026

CVE-2026-63107

Publication date:
20/07/2026
LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey template endpoint that allows authenticated users to cause the server to issue arbitrary HTTP requests by supplying a manipulated Host header. Attackers can exploit the unsanitized use of the HTTP Host header in the getTemplateData() function to reach internal network services, cloud metadata endpoints, and extract sensitive credentials such as IAM tokens from instance metadata services.
Severity CVSS v4.0: MEDIUM
Last modification:
20/07/2026

CVE-2026-61424

Publication date:
20/07/2026
The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.
Severity CVSS v4.0: CRITICAL
Last modification:
21/07/2026

CVE-2026-61425

Publication date:
20/07/2026
The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.
Severity CVSS v4.0: CRITICAL
Last modification:
21/07/2026

CVE-2026-60029

Publication date:
20/07/2026
The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users could break out of id/class fields that render for public users.
Severity CVSS v4.0: MEDIUM
Last modification:
20/07/2026