Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-82671

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability has been found in IObit Unlocker 1.3.0.12. This vulnerability affects the function ZwTerminateProcess in the library IObitUnlocker.sys of the component IRP_MJ_DEVICE_CONTROL Handler. The manipulation leads to improper privilege management. An attack has to be approached locally. The vendor was contacted early about this disclosure but did not respond in any way.
Gravedad CVSS v4.0: MEDIA
Última modificación:
31/08/2026

CVE-2026-82677

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation causes double free. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: b349fe2821e3998534b1454c1b64a478daf8c6b7. To fix this issue, it is recommended to deploy a patch.
Gravedad CVSS v4.0: BAJA
Última modificación:
31/08/2026

CVE-2026-19873

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements.<br /> <br /> When a Repeatable element has counter_name set, its process method reads the repeat count from the named query string parameter, checks only that it is a positive integer, and passes it to repeat, which deep-clones the element&amp;#39;s child subtree once per iteration. Nothing caps the value, and no attribute lets an application impose a limit.<br /> <br /> The count is read on every request, before the form decides whether it was submitted, so a plain GET reaches the clone loop with no credentials, no session and no request body. Nesting multiplies: a Repeatable inside a Repeatable takes a counter at each level, so an outer and an inner value of 100 build 10,000 clones.<br /> <br /> Once the form is submitted, each cloned field&amp;#39;s constraints scan the whole element tree in _find_field_value, so cost grows faster than linearly with the count. A single request exhausts memory and CPU.<br /> <br /> The latest release on CPAN is 2.07, from 2018. Version 2.08 exists only in the git repository.
Gravedad: Pendiente de análisis
Última modificación:
31/08/2026

CVE-2026-49003

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monitoring module to crash and become paralyzed; simultaneously, they can obtain root privileges to steal configuration passwords such as SNMP, thereby tampering with critical system parameters and triggering abnormal operation of the entire power system.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
31/08/2026

CVE-2026-82871

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authenticated user to access other organizations&amp;#39; table schemas and row data. Attackers can supply arbitrary organization IDs in URL parameters to list tables, retrieve column definitions, and execute join queries to read actual stored data from victim organizations.
Gravedad CVSS v4.0: ALTA
Última modificación:
31/08/2026

CVE-2026-82872

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user&amp;#39;s workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another workspace by replacing the organizationId parameter in table-management API requests.
Gravedad CVSS v4.0: ALTA
Última modificación:
31/08/2026

CVE-2026-82874

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across tenant boundaries. Attackers can extract victim organization IDs from public app endpoints, then exploit schema operation endpoints to disclose table schemas, plant malicious tables, corrupt existing schemas, or permanently destroy victim data without any relationship to the target organization.
Gravedad CVSS v4.0: BAJA
Última modificación:
31/08/2026

CVE-2026-82875

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from URL path without verifying it matches the authenticated user&amp;#39;s workspace. Authenticated users can enumerate, create, rename, and delete TooljetDB tables in any other workspace by manipulating the organizationId parameter in requests.
Gravedad CVSS v4.0: MEDIA
Última modificación:
31/08/2026

CVE-2026-82873

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** ToolJet through 3.0.0-ee-beta.2 contains authorization bypass vulnerabilities in the POST /api/v2/resources/export endpoint that allow authenticated users to disclose TooljetDB table schemas across workspace boundaries and export app definitions across granular permission boundaries. Attackers can supply a body-provided organization_id parameter to access schemas from other workspaces, or bypass per-app authorization gates to export restricted app definitions within their workspace.
Gravedad CVSS v4.0: MEDIA
Última modificación:
31/08/2026

CVE-2026-82865

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** pdfme schemas before 5.5.10 contains a cross-site scripting vulnerability in the multiVariableText property panel that assigns unsanitized i18n label values to innerHTML. Attackers who control label overrides through options.labels can inject arbitrary JavaScript that executes when users open the Designer and select a multiVariableText field without variable placeholders.
Gravedad CVSS v4.0: BAJA
Última modificación:
31/08/2026

CVE-2026-82866

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** @pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function that fetches arbitrary URLs without validation when basePdf is attacker-controlled. Attackers who control the basePdf template field can force servers or clients to make requests to internal endpoints, enabling metadata exfiltration, network reconnaissance, and blind request forgery attacks.
Gravedad CVSS v4.0: ALTA
Última modificación:
31/08/2026

CVE-2026-82867

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** @pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the Select schema plugin that fails to sanitize option values before interpolating them into HTML via innerHTML. Attackers can supply malicious templates with crafted option values containing HTML and JavaScript to execute arbitrary code in users&amp;#39; browsers.
Gravedad CVSS v4.0: MEDIA
Última modificación:
31/08/2026