Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-18622

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures.
Gravedad CVSS v3.1: MEDIA
Última modificación:
13/08/2026

CVE-2026-14213

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked customer's personal data.
Gravedad: Pendiente de análisis
Última modificación:
13/08/2026

CVE-2026-18945

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling the related AJAX actions, allowing unauthenticated users to view other customers&amp;#39; order details, including personal information, as well as change the state of arbitrary orders.<br /> <br /> Exploitation requires WooCommerce to be active and the WP Helper Premium WordPress plugin before 4.7.6&amp;#39;s optional order confirmation page module to be enabled.
Gravedad: Pendiente de análisis
Última modificación:
13/08/2026

CVE-2026-19088

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and readable by the attacker.
Gravedad: Pendiente de análisis
Última modificación:
13/08/2026

CVE-2026-3835

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.8.8.8 The method uses a SQL `LIKE` operator for token lookup without escaping wildcard characters via `$wpdb-&gt;esc_like()`. This makes it possible for unauthenticated attackers to bypass the private token requirement by supplying SQL wildcard characters (such as `%`) as the token value, matching any record in the plugin&amp;#39;s file table and downloading any protected file.
Gravedad CVSS v3.1: MEDIA
Última modificación:
13/08/2026

CVE-2026-13328

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is also exposed to unauthenticated users and gated only by a nonce that is publicly available to visitors, allowing unauthenticated attackers to change the status of arbitrary reservations.
Gravedad: Pendiente de análisis
Última modificación:
13/08/2026

CVE-2026-13610

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.
Gravedad: Pendiente de análisis
Última modificación:
13/08/2026

CVE-2026-14182

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered user who has not yet confirmed their email address.
Gravedad: Pendiente de análisis
Última modificación:
13/08/2026

CVE-2026-72506

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnerability. Users may be directed to a server (or service) controlled by an attacker, potentially resulting in the theft of input data or the display of incorrect results.
Gravedad CVSS v4.0: MEDIA
Última modificación:
13/08/2026

CVE-2026-19135

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Measurements REST API that escapes the sandbox and loads arbitrary Java classes on the server. This can potentially allow an attacker to gain access to confidential information and compromise integrity.<br /> <br /> The solution is to upgrade to Meridian 2024.3.12, 2025.0.9 and Horizon 36.0.3 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization&amp;#39;s private networks and should not be directly accessible from the Internet.
Gravedad CVSS v3.1: MEDIA
Última modificación:
13/08/2026

CVE-2026-19182

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows a low-privileged authenticated user (ROLE_REST) to acknowledge, escalate, or clear alarms recorded as an arbitrary username, and, when also assigned ROLE_READONLY, to modify alarm state despite the read-only restriction. A credential check that should restrict these operations is guarded by an inverted condition, so it never executes for a real (non-blank) username. This can potentially allow an attacker to compromise the integrity of alarm state and audit records.<br /> <br /> <br /> <br /> The solution is to upgrade to Meridian 2024.3.12, 2025.0.9 and Horizon 36.0.3 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization&amp;#39;s private networks and should not be directly accessible from the Internet.
Gravedad CVSS v3.1: MEDIA
Última modificación:
13/08/2026

CVE-2026-18728

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local network segment to cause a denial of service. By sending a specially crafted IPv4/UDP DHCP reply, the attacker can trigger an out-of-bounds read, leading to the `iscsiuio` process crashing. This issue affects systems where `iscsiuio` is actively handling IPv4 DHCP traffic.
Gravedad CVSS v3.1: MEDIA
Última modificación:
13/08/2026