Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-53504

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing time. This issue is fixed in 7.8.0.
Gravedad CVSS v3.1: ALTA
Última modificación:
31/07/2026

CVE-2026-53501

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() removes all occurrences of the substring, an attacker can insert the same signature multiple times in the URL and manipulate the final URL used for validation. This allows crafting URLs where the validated string differs from the actual requested resource, enabling loading images from unintended domains or paths. This issue is fixed in 7.8.0.
Gravedad CVSS v3.1: ALTA
Última modificación:
31/07/2026

CVE-2026-53502

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boundary validation, allowing traversal outside FILE_LOADER_ROOT_PATH through watermark or frame filter input. This issue is fixed in 7.8.0.
Gravedad CVSS v4.0: ALTA
Última modificación:
31/07/2026

CVE-2026-18321

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd
Gravedad CVSS v3.1: MEDIA
Última modificación:
31/07/2026

CVE-2026-25552

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a misconfigured Nginx configuration. Attackers can append attacker-controlled values to the header chain using the $proxy_add_x_forwarded_for directive to present an arbitrary IP address, circumventing Ghost's rate-limiting mechanisms on self-hosted instances.
Gravedad CVSS v4.0: MEDIA
Última modificación:
31/07/2026

CVE-2026-18481

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Stored cross-site scripting in the participant URL handling in AWS Ops <br /> Wheel before PR #168 might allow an authenticated remote user to steal <br /> session tokens and escalate to full administrative control of the <br /> deployed instance via a crafted participant_url value containing a <br /> dangerous URI scheme.<br /> <br /> <br /> <br /> <br /> <br /> <br /> To remediate this issue, users should redeploy from the latest version of aws-ops-wheel.
Gravedad CVSS v4.0: MEDIA
Última modificación:
31/07/2026

CVE-2026-54729

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost as safe when DNS resolver 1.1.1.1 returns NXDOMAIN because dns.resolve4 yields no address and no dns.lookup fallback occurs, allowing server-side request forgery. This issue is fixed in version 1.0.5.
Gravedad CVSS v4.0: ALTA
Última modificación:
31/07/2026

CVE-2026-54725

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and MutateSecret call newVaultClient in pkg/webhook/webhook.go, and vault.security.banzaicloud.io/vault-serviceaccount can cause a ServiceAccount JWT to be sent to an attacker-controlled Vault address. This issue is fixed in version 1.23.1.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
31/07/2026

CVE-2026-54737

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** @phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursively merges user-supplied objects without filtering proto, constructor, and prototype, allowing properties to be written to Object.prototype. This issue is fixed in version 2.0.5.
Gravedad CVSS v3.1: ALTA
Última modificación:
31/07/2026

CVE-2026-55100

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query strings instead of using encodeURIComponent() and URLSearchParams, allowing path traversal and query parameter injection. This issue is fixed in version 0.5.2.
Gravedad CVSS v4.0: ALTA
Última modificación:
31/07/2026

CVE-2026-34490

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data.<br /> <br /> This issue affects XAAP Application: before 1.53.
Gravedad CVSS v4.0: MEDIA
Última modificación:
31/07/2026

CVE-2026-34495

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper neutralization of input during web page generation (&amp;#39;cross-site scripting&amp;#39;) vulnerability in Johnson Controls FM Systems Employee allows Stored XSS.<br /> <br /> This issue affects FM Systems Employee: before 2025.3.1.
Gravedad CVSS v4.0: MEDIA
Última modificación:
31/07/2026