Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-6890

Publication date:
31/07/2026
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-14541

Publication date:
31/07/2026
An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience or clientId, the ValidateMCPAuth pipeline for opaque tokens skips audience validation entirely. As a result, the toolbox will accept any valid Google OAuth access token—even those minted for unrelated ecosystem applications—granting unauthorized clients access to protected tools and data backends.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-14540

Publication date:
31/07/2026
A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, the underlying HTTP client (internal/sources/http/http.go) fails to safely regulate request redirection boundaries. Specifically, the client is initialized without a restrictive CheckRedirect policy hook and lacks target IP validation. An attacker or a malicious data-driven prompt can supply a crafted path parameter that triggers an open redirect or a direct destination swap on the target backend, coercing the mcp-toolbox into blindly following the redirection and making unauthorized requests to internal or arbitrary external endpoints.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-14538

Publication date:
31/07/2026
An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation checks. The toolbox relies on the BigQuery dry-run API to enforce dataset restrictions, but due to a fail-open logic flaw, it bypasses validation when the API returns an empty array for specialized constructs. This allows the attacker to extract structural DDL schemas for explicitly excluded datasets via INFORMATION_SCHEMA, and access downstream federated row data via EXTERNAL_QUERY connections.
Severity CVSS v4.0: MEDIUM
Last modification:
31/07/2026

CVE-2026-14539

Publication date:
31/07/2026
An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker to cause a denial of service (DoS). The /mcp endpoint handler reads incoming payloads directly into system memory using an unrestricted buffer loop (io.ReadAll) without applying defensive constraints such as http.MaxBytesReader or pre-read Content-Length enforcement. By submitting a single, massive HTTP request body, an attacker can linearly consume available host memory until the runtime process is terminated by an Out-Of-Memory (OOM) error.
Severity CVSS v4.0: MEDIUM
Last modification:
31/07/2026

CVE-2026-14537

Publication date:
31/07/2026
Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints when the --enable-api flag is active.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-58039

Publication date:
31/07/2026
A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths.<br /> <br /> This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.<br /> <br /> This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-66360

Publication date:
30/07/2026
The ISO Presentation layer contains a flaw in the handling of specific <br /> parameters during normal mode negotiation. A missing length check in the<br /> processing of the encoded presentation data allows an attacker <br /> controlled field with a zero length value to trigger a bounded heap over<br /> read. This condition occurs before MMS session establishment, a crafted<br /> TCP/102 connection attempt can trigger the issue. The resulting over <br /> read causes the process to terminate, leading to a denial of service <br /> condition.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-66364

Publication date:
30/07/2026
The GOOSE payload parser contains a boundary handling flaw that can be <br /> triggered by a single unauthenticated Layer 2 multicast frame on the <br /> process bus. When processing specific payload fields, an attacker <br /> controlled inner element length may exceed its enclosing length, causing<br /> the parser to over read by one byte. This out-of-bounds read reliably <br /> terminates the subscriber process, resulting in a denial-of-service <br /> condition.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-66420

Publication date:
30/07/2026
MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebServerOriginName() function within webserver.js when self-signed certificates are in use. Attackers can open cross-origin WebSocket connections to any of the twelve WebSocket endpoints, send crafted action commands to exfiltrate the server sessionKey used to sign session cookies, forge session tokens as arbitrary users, and gain full remote control of all managed devices governed by the MeshCentral instance.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-66421

Publication date:
30/07/2026
OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator&amp;#39;s browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message containing inline event handler payloads such as an img tag with an onerror attribute within the 60-character rendering budget, which is stored in the session transcript and interpolated unsanitized into innerHTML on the default landing page, allowing theft of session tokens and unauthorized calls to authenticated administrative endpoints including agent instruction file modification.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026

CVE-2026-66720

Publication date:
30/07/2026
The GOOSE subscriber component improperly validates the UTC timestamp <br /> field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 <br /> multicast messages. A specially crafted GOOSE frame containing an <br /> undersized timestamp field can trigger a heap out-of-bounds read during <br /> message processing, causing the process to crash and resulting in a <br /> denial-of-service condition.
Severity CVSS v4.0: HIGH
Last modification:
31/07/2026