Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-54208

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Tobit Laboratories AG TeamDavid&amp;#39;s Webbox application is vulnerable to arbitrary file write, allowing an <br /> unauthenticated attacker to create or write into existing files on the <br /> server with attacker-controlled content. This is possible because user <br /> input is written directly to files without proper validation or <br /> restriction on file types. As a result, an attacker can create files <br /> (e.g., .htm), containing malicious JavaScript code. When a user accesses<br /> a file created in this way, stored cross-site scripting is triggered. This issue affects TeamDavid through Rollout 524.
Gravedad CVSS v4.0: ALTA
Última modificación:
07/08/2026

CVE-2026-54209

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Tobit Laboratories AG TeamDavid&amp;#39;s Webbox application handles password changes using a function triggered by <br /> including the string "(editini)" in the file path, writing the new <br /> password to the specified "Archive.ini" file. However, the application <br /> does not verify that the provided path actually refers to an <br /> "Archive.ini" file. If an attacker specifies a different file with <br /> excessive size, a buffer overflow occurs. This vulnerability allows an <br /> unauthenticated attacker to crash the server, resulting in denial of <br /> service. This issue affects TeamDavid through Rollout 524.
Gravedad CVSS v4.0: ALTA
Última modificación:
07/08/2026

CVE-2026-12071

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input, <br /> which is appended to the redirect target in a 302 HTTP response. By <br /> using URL-encoded characters such as “%2e” (representing a dot), an <br /> attacker can manipulate the portion of the URL following the top-level <br /> domain (TLD). If a similar, registerable TLD exists (for example, if <br /> “.com” is the application’s domain, and “.company” is available for <br /> registration), an attacker can craft a URL to redirect users to a <br /> malicious “.company” domain. By using URL-encoded line feeds, it becomes<br /> possible to insert arbitrary response headers in the server&amp;#39;s HTTP <br /> response.<br /> <br /> <br /> <br /> This issue affects TeamDavid through Rollout 524.
Gravedad CVSS v4.0: MEDIA
Última modificación:
07/08/2026

CVE-2026-54199

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Tobit Laboratories AG TeamDavid&amp;#39;s Webbox is vulnerable to HTTP header injection through the <br /> request body in the application&amp;#39;s link storing functionality <br /> (//ServerClient_celink.htm), which is appended to the redirect target in<br /> the 302 HTTP response. If a line feed is added, this will also be added<br /> to the redirect link, resulting in the ability to control the response <br /> headers. This issue affects TeamDavid through Rollout 524.
Gravedad CVSS v4.0: MEDIA
Última modificación:
07/08/2026

CVE-2026-54200

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Tobit Laboratories AG TeamDavid&amp;#39;s Webbox is vulnerable to a local file inclusion vulnerability in<br /> the send email, fax, SMS, etc. functionality. By specifying an &amp;#39;@@attach&amp;#39; command in the form field &amp;#39;scjob&amp;#39;, files can be attached to a message, <br /> which can then be downloaded by an authenticated user. A filter is in <br /> place that restricts access to the David con-fig folder and the user <br /> folder. However, this filter can be bypassed by specifying an alternate <br /> data stream, allowing the download of sensitive files such as other <br /> users&amp;#39; access files containing their passwords or the server&amp;#39;s private <br /> key. This issue affects TeamDavid through Rollout 524.
Gravedad CVSS v4.0: ALTA
Última modificación:
07/08/2026

CVE-2026-54201

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Tobit Laboratories AG TeamDavid&amp;#39;s Webbox does not enforce authentication or authorization checks<br /> when serving these log files. As a result, attackers can obtain <br /> sensitive error information or internal application details, potentially<br /> aiding in further attacks. This issue affects TeamDavid through Rollout 524.
Gravedad CVSS v4.0: MEDIA
Última modificación:
07/08/2026

CVE-2026-54202

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Tobit Laboratories AG TeamDavid&amp;#39;s Webbox is vulnerable to a path traversal vulnerability in the <br /> archive creation functionality. Because the archive path is <br /> user-controlled and insufficiently validated, an attacker can manipulate<br /> the input to traverse directories. This allows the creation of folders <br /> in arbitrary locations, including sensitive directories such as <br /> C:\Windows or for different users. This issue affects TeamDavid through Rollout 524.
Gravedad CVSS v4.0: ALTA
Última modificación:
07/08/2026

CVE-2026-12070

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Tobit Laboratories AG TeamDavid&amp;#39;s Webbox is vulnerable to an arbitrary file deletion <br /> vulnerability in the send email, fax, SMS, etc. functionality. By <br /> specifying an @@COMMENTFILE command in the form field scjob, any file on<br /> the system can be deleted. This issue affects TeamDavid through Rollout 524.
Gravedad CVSS v4.0: ALTA
Última modificación:
07/08/2026

CVE-2026-66491

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an arbitrary file read vulnerability.
Gravedad CVSS v4.0: ALTA
Última modificación:
07/08/2026

CVE-2026-66492

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the file upload action lead to path a traversal vulnerability.
Gravedad CVSS v4.0: MEDIA
Última modificación:
07/08/2026

CVE-2026-66493

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths for delete, copy and move actions lead to path traversal vulnerabilities.
Gravedad CVSS v4.0: MEDIA
Última modificación:
07/08/2026

CVE-2026-9169

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH environment variable, which the SDK traverses when a required dependency is not found locally.
Gravedad CVSS v3.1: ALTA
Última modificación:
07/08/2026