Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-62323

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the session-id prefix of a WOPI access token and does not enforce the requested viewer action, allowing a malicious or compromised WOPI viewer with a view session to forge the token suffix and invoke WOPI write routes for the underlying file. This issue is fixed in version 4.17.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
31/07/2026

CVE-2026-63220

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an attacker could spoof these headers and cause the application to incorrectly treat an HTTP request as secure. This may have impacted applications that rely on isSecure(), force_https(), forceGlobalSecureRequests, or similar logic to enforce HTTPS-only access or make security-sensitive decisions. Exploitability depends on deployment configuration. Applications are most exposed if the backend is reachable directly over HTTP, or if a reverse proxy/load balancer forwards client-supplied forwarding headers without stripping or overwriting them. This issue has been fixed in version 4.7.4.
Gravedad CVSS v3.1: MEDIA
Última modificación:
31/07/2026

CVE-2026-55497

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed file size but do not limit decoded pixel dimensions, allowing an authenticated user to submit a small PNG, JPEG, or GIF that triggers an unbounded allocation and terminates the Cloudreve process through fatal out-of-memory behavior. This issue is fixed in version 4.17.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
31/07/2026

CVE-2026-55499

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscription resolves the share root to the owner’s parent folder and subscribes to that folder topic, allowing an authenticated share recipient to receive names, paths, rename targets, event types, and hashed identifiers for unshared sibling files and folders. This issue is fixed in version 4.17.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
31/07/2026

CVE-2026-55502

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetOauthRedirectService persists caller-supplied OneDrive secret and app_id values, allowing an OAuth token without Admin.Write to modify storage policy credentials. The route is inside the admin group that requires Admin.Read, but it does not add the local Admin.Write guard used by sibling policy mutation routes. Its handler persists attacker-supplied secret and app_id values into the selected OneDrive storage policy before returning an OAuth URL. This issue is fixed in version 4.17.0.
Gravedad CVSS v3.1: ALTA
Última modificación:
31/07/2026

CVE-2026-43832

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Successful exploitation of the<br /> vulnerability could allow an unauthenticated attacker to exploit a stack-based<br /> buffer overflow in the Cookie parsing methods to conduct code execution when<br /> the SafeEnhancement feature is enabled.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
31/07/2026

CVE-2026-43833

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Successful exploitation of the vulnerability<br /> could allow an authenticated attacker to exploit a stack-based buffer overflow<br /> in the upload functionality to conduct code execution.
Gravedad CVSS v4.0: ALTA
Última modificación:
31/07/2026

CVE-2026-55495

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than a filename, allowing slash and dot-dot segments to escape the source file directory and create or conditionally overwrite files elsewhere in the same owner account. This issue is fixed in version 4.17.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
31/07/2026

CVE-2026-55496

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActive without adding a StatusActive predicate and serializes matches at RedactLevelUser, allowing any logged-in user to enumerate email addresses and profile metadata for inactive or banned accounts. The service calls userClient.SearchActive, but despite its name that method filters only by email/nickname keyword and never adds a StatusActive predicate — while the sibling lookups GetActiveByID and GetActiveByDavAccount, defined a few lines above it, do. Search hits are serialized at RedactLevelUser, which includes the email address. This issue is fixed in version 4.17.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
31/07/2026

CVE-2026-43830

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Successful exploitation of the<br /> command injection vulnerability could allow an attacker to execute arbitrary<br /> commands during the firmware upgrade file verification process.
Gravedad CVSS v4.0: ALTA
Última modificación:
31/07/2026

CVE-2026-43831

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Successful<br /> exploitation of the vulnerability could allow an unauthenticated attacker to<br /> exploit a stack-based buffer overflow in the log message functionality to<br /> conduct code execution.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
31/07/2026

CVE-2026-43829

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Successful<br /> exploitation of the vulnerability could allow an unauthenticated attacker to<br /> exploit a stack-based buffer overflow in the password functionality to conduct<br /> code execution when the SafeEnhancement feature is enabled.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
31/07/2026