Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-12503

Publication date:
24/07/2026
Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `larmapp` attacker to make `/etc/passwd` writable by the `larmapp` group (leading to root privilege escalation) via a symlink attack on `/etc/lighttpd/ssl/server.pem`.
Severity CVSS v4.0: CRITICAL
Last modification:
24/07/2026

CVE-2026-12496

Publication date:
24/07/2026
Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to execute arbitrary JavaScript in an administrator's browser (session hijacking, credential theft, device reconfiguration) via a crafted `User-Agent` header in a `POST /da` request.
Severity CVSS v4.0: HIGH
Last modification:
24/07/2026

CVE-2026-17048

Publication date:
24/07/2026
A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.
Severity CVSS v4.0: Pending analysis
Last modification:
24/07/2026

CVE-2026-9765

Publication date:
24/07/2026
Note: The CVE and blog post don&amp;#39;t exist because we determined this is actually a cloud-only issue.<br /> <br /> Access Controls are “Broken” when a user can access resources they are not authorized to access. An attacker can bypass any access control mechanisms in a web application, and gain unauthorized access to resources that are not available with their permissions. <br /> <br /> Broken access control can allow attackers to:<br /> Access resources only accessible to certain users, thus allowing unauthorized access to data<br /> Perform operations on behalf of other users, leading to account takeovers in the worst cases<br /> Attempt privilege escalation<br /> Attempt to take over an account
Severity CVSS v4.0: Pending analysis
Last modification:
24/07/2026

CVE-2026-7484

Publication date:
24/07/2026
External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co. AVESİS allows Accessing Functionality Not Properly Constrained by ACLs.<br /> <br /> This issue affects AVESİS: before 202606251646.
Severity CVSS v4.0: Pending analysis
Last modification:
24/07/2026

CVE-2026-66142

Publication date:
24/07/2026
Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3, which fixes this issue.
Severity CVSS v4.0: Pending analysis
Last modification:
24/07/2026

CVE-2026-66143

Publication date:
24/07/2026
It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upgrade to version 3.2.3, which fixes this issue.
Severity CVSS v4.0: Pending analysis
Last modification:
24/07/2026

CVE-2026-66144

Publication date:
24/07/2026
Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, which fixes this issue by imposing a default maximum size on data read from remote policy references.
Severity CVSS v4.0: Pending analysis
Last modification:
24/07/2026

CVE-2026-66008

Publication date:
24/07/2026
Parse Server versions &gt;= 9.0.0 before 9.10.0-alpha.6 and &gt;= 8.2.2 before 8.6.87 disclose Pointer and Relation target class names through GraphQL validation and input-coercion error messages when public schema introspection is disabled (graphQLPublicIntrospection: false, the default). Because these errors are produced before authentication, authorization, or any resolver runs, an unauthenticated client possessing only the public application ID can trigger errors on Pointer or Relation fields to reconstruct hidden schema class names, partially defeating the schema-hiding protection. Only schema metadata (class names) is exposed; no object data, credentials, or user records are disclosed.
Severity CVSS v4.0: MEDIUM
Last modification:
24/07/2026

CVE-2026-66010

Publication date:
24/07/2026
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
Severity CVSS v4.0: MEDIUM
Last modification:
24/07/2026

CVE-2026-66009

Publication date:
24/07/2026
Parse Server versions &gt;= 9.0.0 before 9.10.0-alpha.5 and &gt;= 8.2.2 before 8.6.86 return GraphQL validation error messages that name required custom input fields even when public introspection is disabled (graphQLPublicIntrospection: false, the default). A client holding only the public application id — with no user session, master key, or maintenance key — can trigger validation errors to learn the names of required (non-null) custom fields on classes it already references by name, partially defeating the schema-hiding intent of disabling public introspection. No stored data, credentials, optional field names, unreferenced class names, or Cloud Code function names are exposed.
Severity CVSS v4.0: MEDIUM
Last modification:
25/07/2026

CVE-2026-46452

Publication date:
24/07/2026
Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken data toward application resulting in memory pressure and unstable parsing behavior.<br /> <br /> This issue affects Apache NimBLE: through 1.9.0.<br /> <br /> Users are recommended to upgrade to version 1.10.0, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
24/07/2026