Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-75773

Fecha de publicación:
18/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was found in karakeep-app karakeep up to 0.32.0. The affected element is the function authorize of the file apps/web/server/auth.ts of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been made public and could be used. Upgrading to version 0.33.0 is sufficient to fix this issue. The patch is identified as f7d042971d0d2bcc7119654830cf1eb93eabbf24. It is advisable to upgrade the affected component.
Gravedad CVSS v4.0: BAJA
Última modificación:
18/08/2026

CVE-2026-75626

Fecha de publicación:
18/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation results that execute scripts in the operator's browser when the correlations view is opened, potentially stealing API keys.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
18/08/2026

CVE-2026-18929

Fecha de publicación:
18/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when processing .docx files. The library uses yazl for zip decompression without validating entry sizes, allowing an attacker to supply a malicious .docx file containing a zip bomb that decompresses to a significantly larger size, causing excessive memory consumption and crashing the application server.<br /> <br /> <br /> <br /> <br /> The issue was fixed in versions: 3.8.2, 4.26.3 and 5.4.4.  The fix is available across all distribution types.
Gravedad CVSS v4.0: MEDIA
Última modificación:
18/08/2026

CVE-2026-43971

Fecha de publicación:
18/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via unescaped special characters in cow_link:link/1.<br /> <br /> cow_link:do_link/1 in cowlib interpolates the target URI, rel value, and attribute keys directly into the serialized Link: header value without escaping or token-grammar validation. A &gt; byte in target prematurely closes the URI slot, allowing an attacker to append additional link entries with attacker-chosen rel directives. A " or \ in rel escapes the quoted string and opens new parameters. Any byte — including whitespace, =, and " — in an attribute key is emitted verbatim. Because browsers act on Link: directives such as rel="preconnect", rel="preload", and rel="prerender", an attacker who can influence these fields in an application that round-trips parsed Link headers through cow_link:link/1 can force victim browsers to make out-of-band connections to attacker-controlled origins.<br /> <br /> This issue affects cowlib: from 2.9.0 onward.
Gravedad CVSS v4.0: MEDIA
Última modificación:
18/08/2026

CVE-2024-14045

Fecha de publicación:
18/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Product Supplier Edit Controller. Executing a manipulation can lead to improper authorization. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.9.3 is able to resolve this issue. This patch is called f767ac1a5987d4865d9f158c6a967680f8e45468. It is suggested to upgrade the affected component.
Gravedad CVSS v4.0: BAJA
Última modificación:
18/08/2026

CVE-2026-34884

Fecha de publicación:
18/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP.<br /> <br /> <br /> <br /> <br /> <br /> This issue affects Apache SkyWalking MCP: 0.1.0.<br /> <br /> Users are recommended to upgrade to version 0.2.0, which fixes this issue.
Gravedad: Pendiente de análisis
Última modificación:
18/08/2026

CVE-2026-15371

Fecha de publicación:
18/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Velociraptor&amp;#39;s web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked in the GUI.The code does not limit the schemes allowed in this URL , allowing an attacker to specify a JavaScript scheme exposing the user to XSS.
Gravedad CVSS v3.1: ALTA
Última modificación:
18/08/2026

CVE-2026-75091

Fecha de publicación:
18/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Quill Forms | Conversational Multi Step Forms, Surveys &amp; quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Gravedad CVSS v3.1: ALTA
Última modificación:
18/08/2026

CVE-2026-15748

Fecha de publicación:
18/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field configuration injected via a forged Select field value. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
18/08/2026

CVE-2026-75151

Fecha de publicación:
18/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability has been found in SourceCodester Onlne Examination &amp; Learning Management System 1.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be initiated remotely.
Gravedad CVSS v4.0: MEDIA
Última modificación:
18/08/2026

CVE-2026-11801

Fecha de publicación:
18/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve internal site configuration data exposed by the classifieds-types REST endpoint, including registered post types, labels, associated taxonomies, form scheme metadata, contact options, and custom field meta keys.
Gravedad CVSS v3.1: ALTA
Última modificación:
18/08/2026

CVE-2026-75090

Fecha de publicación:
18/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was detected in EricLBuehler Mistral.rs up to 0.8.22. Affected by this issue is the function convert_gguf_to_hf_tokenizer of the file mistralrs-core/src/gguf/gguf_tokenizer.rs of the component GGUF Tokenizer. The manipulation of the argument eos_token_id/bos_token_id/unknown_token_id results in out-of-bounds read. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 0.8.23 can resolve this issue. The patch is identified as cd5297e2ea5cb27c790bdcf2f3c2f1064a81d55e. Upgrading the affected component is recommended.
Gravedad CVSS v4.0: BAJA
Última modificación:
18/08/2026