Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-65438

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7
Gravedad CVSS v3.1: ALTA
Última modificación:
27/07/2026

CVE-2026-65439

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7
Gravedad CVSS v3.1: ALTA
Última modificación:
27/07/2026

CVE-2026-65440

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Unauthenticated Cross Site Scripting (XSS) in GetGenie
Gravedad CVSS v3.1: ALTA
Última modificación:
27/07/2026

CVE-2025-63913

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU extension.
Gravedad: Pendiente de análisis
Última modificación:
27/07/2026

CVE-2026-59240

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The vulnerability involves an Insecure Direct Object Reference (IDOR) in the `DeleteNotificationController::delete()` method at endpoint `GET /notification/delete/{id}`. The flaw allows any authenticated user, regardless of company or permissions, to delete notifications belonging to any other user in the system. The controller retrieves the target record with `Notification::findOrFail($id)` and deletes it without validating `user_id` or `company_id` ownership, unlike the sibling `SetNotificationReadAjaxController`, which correctly scopes lookups by `Auth::id()`. Because notification identifiers are sequential, an attacker can iterate over IDs to systematically delete notifications belonging to any user, denying them visibility of ticket alerts, task assignments, and other system events.
Gravedad CVSS v4.0: MEDIA
Última modificación:
27/07/2026

CVE-2026-55685

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times. This issue is a follow up to CVE-2026-42342, and does not does not impact React Router applications using Declarative Mode () or Data Mode (createBrowserRouter/). This issue has been fixed in version 7.18.0.
Gravedad CVSS v4.0: ALTA
Última modificación:
27/07/2026

CVE-2026-53667

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. This issue is a follow up to CVE-2026-53667, and only affects consuming applications if they are using the unstable RSC APIs. This issue has been fixed in version 7.18.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/07/2026

CVE-2026-53668

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker could craft a malicious link that redirects users to an unexpected external site or that exploits an XSS vector.This issue has been fixed in version 7.13.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/07/2026

CVE-2026-53669

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in and useNavigate. This issue is a follow up to CVE-2025-68470 and has been fixed in version 7.18.0.
Gravedad CVSS v4.0: MEDIA
Última modificación:
27/07/2026

CVE-2026-51077

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the sqlquery parameter of the sys_sql_query.php component
Gravedad: Pendiente de análisis
Última modificación:
27/07/2026

CVE-2026-51078

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the str parameter of the file_manage_control.php component
Gravedad: Pendiente de análisis
Última modificación:
27/07/2026

CVE-2026-51564

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An issue in the redirect parameter in Milk admin
Gravedad: Pendiente de análisis
Última modificación:
27/07/2026