Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-8082

Fecha de publicación:
21/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce order submission, allowing unauthenticated attackers to perform time-based blind SQL injection on stores running this bpost-shipping-platform WordPress plugin before 3.2.3.
Gravedad: Pendiente de análisis
Última modificación:
21/07/2026

CVE-2026-11767

Fecha de publicación:
21/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputting them in the admin dashboard, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks that execute when a logged-in administrator views the form submissions.
Gravedad: Pendiente de análisis
Última modificación:
21/07/2026

CVE-2026-13693

Fecha de publicación:
21/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a notification email, allowing unauthenticated attackers to read arbitrary server files such as the WordPress configuration file.
Gravedad: Pendiente de análisis
Última modificación:
21/07/2026

CVE-2026-13694

Fecha de publicación:
21/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing unauthenticated attackers to re-trigger a form's configured workflow actions such as notification emails and integrations.
Gravedad: Pendiente de análisis
Última modificación:
21/07/2026

CVE-2026-13439

Fecha de publicación:
21/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier ('sid') as the password reset token stored in wp_emsfb_temp_links, combined with a publicly-accessible nonce refresh endpoint (Emsfb/v1/nonce/refresh) that issues valid WordPress REST nonces to unauthenticated visitors. This makes it possible for unauthenticated attackers to reset the password of any WordPress user — including administrators — by scraping the public sid from a published login form page, submitting a recovery request for any known user email via Emsfb/v1/forms/message/add, and then calling Emsfb/v1/forms/recovery/efb_set_password with the known sid to set an arbitrary new password and gain full administrator access.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
21/07/2026

CVE-2026-15782

Fecha de publicación:
21/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the OptinMonster plugin to be installed and configured with an active inline campaign that outputs matching #om-{id} markup on the target page, as the WPForms handler only fires when OptinMonster emits its 'om.Campaign.load' event.
Gravedad CVSS v3.1: MEDIA
Última modificación:
21/07/2026

CVE-2026-15811

Fecha de publicación:
21/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was found in kronosnet's (version
Gravedad CVSS v3.1: MEDIA
Última modificación:
21/07/2026

CVE-2026-15812

Fecha de publicación:
21/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected:
Gravedad CVSS v3.1: MEDIA
Última modificación:
21/07/2026

CVE-2026-15927

Fecha de publicación:
21/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in Red Hat Quay&amp;#39;s repository-level mirror configuration<br /> feature. The POST and PUT handlers in endpoints/api/mirror.py accept an<br /> external_reference parameter without SSRF validation, unlike the<br /> organization-level mirror handlers which apply validate_external_registry_url().<br /> A repository administrator can supply a crafted hostname that causes the Quay<br /> mirror worker to make requests via Skopeo to internal network services, cloud<br /> metadata endpoints, or other resources not intended to be reachable from the<br /> Quay application.
Gravedad CVSS v3.1: MEDIA
Última modificación:
21/07/2026

CVE-2026-16266

Fecha de publicación:
21/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript prototype chain by supplying a crafted property path containing special keys such as __proto__.
Gravedad CVSS v4.0: MEDIA
Última modificación:
21/07/2026

CVE-2026-3182

Fecha de publicación:
21/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.
Gravedad CVSS v3.1: MEDIA
Última modificación:
21/07/2026

CVE-2023-37507

Fecha de publicación:
21/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.
Gravedad CVSS v4.0: MEDIA
Última modificación:
21/07/2026