Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-47851

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread.<br /> Spring AI 2.0.0<br /> Spring AI 1.1.0 - 1.1.8<br /> Spring AI 1.0.0 - 1.0.9
Gravedad CVSS v3.1: ALTA
Última modificación:
27/08/2026

CVE-2026-47852

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file.<br /> Spring AI 2.0.0<br /> Spring AI 1.1.0 - 1.1.8<br /> Spring AI 1.0.0 - 1.0.9
Gravedad CVSS v3.1: ALTA
Última modificación:
27/08/2026

CVE-2026-47856

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Spring Integration&amp;#39;s JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that header value to a class with ClassUtils.forName and no type/package allow-list.<br /> Spring Integration 7.1.0<br /> Spring Integration 7.0.0 - 7.0.5<br /> Spring Integration 6.5.0 - 6.5.10<br /> Spring Integration 6.4.0 - 6.4.12<br /> Spring Integration 5.5.21 and earlier
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/08/2026

CVE-2026-47857

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition.<br /> Reactor Core 3.8.0 - 3.8.6<br /> Reactor Core 3.5.0 - 3.7.19<br /> Reactor Core 3.4.41 and earlier
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/08/2026

CVE-2026-47859

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frames, trusts the sender-supplied octet count of an octet-counted frame and allocates a byte array of exactly that size with no upper bound.<br /> Spring Integration 7.1.0<br /> Spring Integration 7.0.0 - 7.0.5<br /> Spring Integration 6.5.0 - 6.5.10<br /> Spring Integration 6.4.0 - 6.4.12<br /> Spring Integration 5.5.21 and earlier
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/08/2026

CVE-2026-47845

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. In order for this to happen, the application must be configured to use HAProxy Protocol.<br /> Reactor Netty 1.3.0 - 1.3.6<br /> Reactor Netty 1.1.0 - 1.2.18<br /> Reactor Netty 1.0.52 and earlier
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/08/2026

CVE-2026-47850

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP PUT against an immutable target type.<br /> Spring Data REST 5.1.0<br /> Spring Data REST 5.0.0 - 5.0.6<br /> Spring Data REST 4.5.0 - 4.5.12<br /> Spring Data REST 4.0.0 - 4.4.15<br /> Spring Data REST 3.7.20 and earlier
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/08/2026

CVE-2026-80158

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the ipa_getkeytab module of the community.general<br /> Ansible collection. The module&amp;#39;s bind_pw parameter, used to supply the LDAP simple-bind password when retrieving a Kerberos keytab, is not declared with no_log, unlike the sibling password parameter in the same module. As a consequence, the supplied IPA/LDAP bind password is recorded in cleartext in the managed host&amp;#39;s system journal/syslog (the module&amp;#39;s "Invoked with" record), is included in the module&amp;#39;s return values and verbose (-v) output, and is displayed in Automation Controller / AWX job output. The password is additionally passed on the command line to the ipa-getkeytab helper (as --bindpw ), exposing it in the process list to local users while the command runs. An attacker able to read these logs, job output, or the process table can obtain the directory bind credential, potentially compromising the accounts and objects that credential can access.
Gravedad CVSS v3.1: MEDIA
Última modificación:
26/08/2026

CVE-2026-81203

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Gravedad CVSS v4.0: MEDIA
Última modificación:
26/08/2026

CVE-2026-75340

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF).
Gravedad: Pendiente de análisis
Última modificación:
26/08/2026

CVE-2026-75330

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server
Gravedad: Pendiente de análisis
Última modificación:
26/08/2026

CVE-2026-75332

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Zyplayer-Doc
Gravedad: Pendiente de análisis
Última modificación:
26/08/2026