Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-44615

Publication date:
31/07/2026
Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a note, or access to folder operations, could supply traversal segments in note or folder paths.                   Zeppelin composed these values into filesystem paths using the server's filesystem or Hadoop identity without ensuring that the result remained under the configured notebook directory. This could allow notebook files or directories to be moved,                   written, or deleted outside the notebook root. This issue affects Apache Zeppelin versions 0.9.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-16843

Publication date:
31/07/2026
Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-17567

Publication date:
31/07/2026
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.8 via the 'transaction' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to brute-force valid transaction hashes and view sensitive payment receipt data including customer name, email address, billing address, order items, payment method, and payment status belonging to other users. Because submission ID, form ID, and transaction creation time are either observable or guessable by an attacker, the effective brute-force space is bounded to approximately 900 candidates per second per (submission, form) pair, making exploitation practical without any prior authentication or account.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-18437

Publication date:
31/07/2026
The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to update contact details.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-18436

Publication date:
31/07/2026
The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign//restore-revision/). The route in the vulnerable range was registered without a permissionCallback, allowing the restoreRevision() handler to run for unauthenticated requests and overwrite a campaign's content_html with any prior revision. This makes it possible for unauthenticated attackers to modify campaign content by restoring an arbitrary revision.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-11770

Publication date:
31/07/2026
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-15722

Publication date:
31/07/2026
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-10079

Publication date:
31/07/2026
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causing ACS to treat the workload as having empty UID, name and labels and namespace "default". This bypasses deploy-time policy detection and enforcement visibility, prevents correct persistence in Central and breaks violation reporting and compliance correlation for the affected deployment.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-65313

Publication date:
31/07/2026
A provisioning script used when installing HIPASE-250 (formerly 250<br /> SCALA) engineering workstations sets a fixed, hard-coded x11vnc<br /> password. Because the same credential is applied to every workstation<br /> provisioned this way, an attacker with adjacent-network access who<br /> knows the password can gain VNC access to affected workstations.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-65310

Publication date:
31/07/2026
ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration<br /> of affected versions, exposes its data and configuration endpoint<br /> without any authentication and permissive CORS on every response. An<br /> unauthenticated attacker with network access can read live process<br /> values and server configuration.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-65311

Publication date:
31/07/2026
The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA)<br /> in affected versions exposes an undocumented endpoint that changes<br /> the server&amp;#39;s logging level and target without requiring<br /> authentication. A remote, unauthenticated attacker with network<br /> access to the service may suppress audit logging, potentially<br /> concealing other activity on the system.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026

CVE-2026-18218

Publication date:
31/07/2026
A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the overall security realm already has an older, non-zero revocation policy in place. This issue can allow previously issued tokens to remain valid for refreshing sessions and accessing user information even after an administrator has attempted to invalidate them.<br /> ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2026