Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-69414

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &amp;quot;ShieldBreak &amp;quot;.<br /> We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.
Gravedad CVSS v3.1: ALTA
Última modificación:
14/08/2026

CVE-2026-73682

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository git_url handling that allows authenticated users holding the Manager or Owner role on any project to achieve remote code execution on the Semaphore server host. Attackers can craft a malicious git_url value using git&amp;#39;s --upload-pack= option to inject and execute arbitrary shell commands when the server processes repository operations using the default cmd_git client.
Gravedad CVSS v4.0: ALTA
Última modificación:
14/08/2026

CVE-2026-74248

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project&amp;#39;s QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All Octavia deployments are affected.
Gravedad CVSS v3.1: MEDIA
Última modificación:
14/08/2026

CVE-2026-71570

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration
Gravedad CVSS v4.0: MEDIA
Última modificación:
14/08/2026

CVE-2026-67366

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda
Gravedad CVSS v4.0: MEDIA
Última modificación:
14/08/2026

CVE-2026-50523

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper neutralization of special elements used in a command (&amp;#39;command injection&amp;#39;) in Microsoft PowerShell allows an authorized attacker to execute code locally.
Gravedad CVSS v3.1: ALTA
Última modificación:
14/08/2026

CVE-2026-73680

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the assets/upload permission to execute arbitrary commands by uploading a video file with a shell metacharacter-laden filename. The unsanitized filename is interpolated into a shell command executed via Process::fromShellCommandline() before the slugify() sanitizer runs, enabling injected shell metacharacters such as backticks, $(), and semicolons to escape the FFmpeg command context and execute as the web-server user.
Gravedad CVSS v4.0: ALTA
Última modificación:
14/08/2026

CVE-2026-71571

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter in iCagenda
Gravedad CVSS v4.0: ALTA
Última modificación:
14/08/2026

CVE-2026-64887

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic Attack.<br /> <br /> This issue affects Airwall: before 4.1.
Gravedad CVSS v4.0: ALTA
Última modificación:
14/08/2026

CVE-2026-67365

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
14/08/2026

CVE-2026-19908

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information and modify configuration on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability.<br /> <br /> The specific flaw exists within the XCB daemon. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-30584.
Gravedad CVSS v3.1: ALTA
Última modificación:
14/08/2026

CVE-2026-19909

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability.<br /> <br /> The specific flaw exists within the parsing of AIP files. By creating a symbolic link, an attacker can abuse the installer process to write arbitrary files. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-30583.
Gravedad CVSS v3.1: ALTA
Última modificación:
14/08/2026