Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-69255

Publication date:
04/08/2026
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(',').pop() and interpolated it directly into executable Python as base64_string = "${base64String}" before calling Pyodide. The validatePythonCodeForDataFrame() denylist only checked later LLM-generated code and did not validate this initial code block. An authenticated attacker could inject a closing quote followed by Python code, use Pyodide's js bridge to load Node.js child_process, and execute arbitrary operating system commands as root in the Flowise container. This issue is fixed in version 3.1.3.
Severity CVSS v4.0: CRITICAL
Last modification:
04/08/2026

CVE-2026-69256

Publication date:
04/08/2026
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed through pyodide; although a denylist blocked dangerous Python constructs, pandas.read_pickle() could deserialize a pickled payload and achieve code execution without matching the denied words. The affected file is flowise-components/nodes/agents/CSVAgent/CSVAgent.ts, where user-supplied customReadCSVFunc is evaluated as pd.${customReadCSVFunc}. An authenticated user who can create or modify a chatflow can add a CSV Agent, place a malicious read_pickle payload in the Additional Parameters, save the chatflow, and trigger /api/v1/prediction/ to execute commands. This issue is fixed in version 3.1.3.
Severity CVSS v4.0: CRITICAL
Last modification:
04/08/2026

CVE-2026-69257

Publication date:
04/08/2026
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.254.169.254 before checking them against the deny list. Because ipaddr.js reports these addresses as ipv6 while IPv4 CIDR deny-list entries are ipv4, isDeniedIP() skipped the IPv4 CIDR checks. An attacker who controls DNS resolution for a hostname used by the HTTP Node, API Chain, Document Loader, MCP tool, or other paths using secureAxiosRequest(), secureFetch(), or checkDenyList() could return a AAAA record for an IPv4-mapped target and cause requests to reach localhost, internal services, or cloud metadata endpoints. This issue is fixed in version 3.1.3.
Severity CVSS v4.0: HIGH
Last modification:
04/08/2026

CVE-2026-64631

Publication date:
04/08/2026
A vulnerability allowing a low-privileged user to inject SQL and extract database contents.
Severity CVSS v4.0: HIGH
Last modification:
04/08/2026

CVE-2026-64633

Publication date:
04/08/2026
A vulnerability allowing remote unauthenticated code execution on the agent host.
Severity CVSS v4.0: CRITICAL
Last modification:
04/08/2026

CVE-2026-64634

Publication date:
04/08/2026
A vulnerability allowing local privilege escalation to the Reporter service context.
Severity CVSS v4.0: HIGH
Last modification:
04/08/2026

CVE-2026-58074

Publication date:
04/08/2026
A vulnerability allowing a high-privileged user to execute arbitrary code on the server.
Severity CVSS v4.0: HIGH
Last modification:
04/08/2026

CVE-2026-58075

Publication date:
04/08/2026
A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.
Severity CVSS v4.0: HIGH
Last modification:
04/08/2026

CVE-2026-63455

Publication date:
04/08/2026
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2026

CVE-2026-63456

Publication date:
04/08/2026
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2026

CVE-2026-64630

Publication date:
04/08/2026
A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.
Severity CVSS v4.0: MEDIUM
Last modification:
04/08/2026

CVE-2026-56848

Publication date:
04/08/2026
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free.<br /> <br /> This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2026