Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-47837

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server&amp;#39;s /monitor endpoint are not validated.<br /> <br /> This issue affects Spring Cloud Config: from 5.0.0 through 5.0.4, from 4.3.0 through 4.3.4, from 4.0.0 through 4.2.8, and through 3.1.14.
Gravedad CVSS v3.1: MEDIA
Última modificación:
28/08/2026

CVE-2026-47841

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An application using Spring Security&amp;#39;s WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store.<br /> Spring Security 7.1.0<br /> Spring Security 7.0.0 - 7.0.6<br /> Spring Security 6.5.0 - 6.5.11<br /> Spring Security 6.4.0 - 6.4.18
Gravedad CVSS v3.1: ALTA
Última modificación:
28/08/2026

CVE-2026-32639

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section&amp;#39;s Theme Editor AJAX handlers did not enforce per-template-type permission checks, allowing a backend user with any single CMS permission to act on template types outside their authorized scope. The CMS controller gated access to the section as a whole using OR-logic across its five permissions, but individual handlers such as onSave(), onDelete(), and onDeleteTemplates() did not verify that the user held the specific permission for the requested template type, so a user with only cms.manage_pages could craft AJAX requests to delete layouts, modify partials, or read content files. Separately, the AssetList widget was registered for any user who passed the controller gate regardless of the cms.manage_assets permission, and its onUpload() handler omitted the theme-validation call present on the other mutating handlers, permitting unauthorized file uploads into the active theme&amp;#39;s asset directory. Exploitation requires an authenticated backend account holding at least one of the CMS Theme Editor permissions. This issue is fixed in version 1.2.13.
Gravedad CVSS v3.1: MEDIA
Última modificación:
29/08/2026

CVE-2026-32593

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend Filter widget is vulnerable to SQL injection through the numberrange scope type when that scope is configured with a conditions key, allowing an authenticated backend user to inject arbitrary SQL. The scope&amp;#39;s filter values are interpolated into the conditions statement without parameter binding, so a user with access to a list view whose filter uses this scope and configuration can supply crafted input through the filter&amp;#39;s AJAX handler and read arbitrary database contents. No built-in Winter CMS backend views use this scope type and configuration combination, so exploitation requires a third-party plugin to have registered a numberrange filter scope with a conditions key, and a vanilla installation without such plugins is not affected. This issue is fixed in version 1.2.13.
Gravedad CVSS v3.1: MEDIA
Última modificación:
26/08/2026

CVE-2025-56798

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.&amp;#39;s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication cookie&amp;#39;s lax same-site policy.
Gravedad CVSS v3.1: ALTA
Última modificación:
27/08/2026

CVE-2023-42179

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process.
Gravedad: Pendiente de análisis
Última modificación:
26/08/2026

CVE-2025-29419

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.
Gravedad: Pendiente de análisis
Última modificación:
26/08/2026

CVE-2026-80153

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Gravedad: Pendiente de análisis
Última modificación:
26/08/2026

CVE-2026-35445

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend did not validate the handler name submitted through the form postback _handler POST field, allowing an authenticated backend user to invoke arbitrary controller methods, including protected, private, and action-prefixed ones. While AJAX requests validate that handler names match the on[A-Z][\w+]* pattern, the postback path passed the submitted _handler value straight to the handler dispatcher with no such check, so any controller that exposes a public action or conditionally relaxes its $requiredPermissions check could be reached, bypassing the roles and permissions system. The built-in Users controller was affected because it set $requiredPermissions to null for the myaccount action, letting any authenticated backend user invoke user-management methods such as update_onDelete and update_onManualPasswordReset without holding the backend.manage_users permission. This issue is fixed in version 1.2.13.
Gravedad CVSS v4.0: ALTA
Última modificación:
26/08/2026

CVE-2026-32258

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by the LESS parser and rendered without sanitization on every backend page, allowing stored cross-site scripting. This issue is fixed in version 1.2.13.
Gravedad CVSS v3.1: ALTA
Última modificación:
26/08/2026

CVE-2026-32257

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission is compiled by the LESS parser and rendered without sanitization on every backend page, allowing stored cross-site scripting against backend users. This issue is fixed in version 1.2.13.
Gravedad CVSS v3.1: ALTA
Última modificación:
27/08/2026

CVE-2020-15876

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the sort parameter in the /ajax_table.php API endpoint. This affects address-search.inc.php, alertlog.inc.php, arp-search.inc.php, as-selection.inc.php, bills.inc.php, device_mibs.inc.php, device_oids.inc.php, edit-ports.inc.php, eventlog.inc.php, inventory.inc.php, ix-list.inc.php, ix-peers.inc.php, mempool-edit.inc.php, mempool.inc.php, mibs.inc.php, poll-log.inc.php, processor-edit.inc.php, processor.inc.php, routing-edit.inc.php, sensors-common.inc.php, storage-edit.inc.php, storage.inc.php, tnmsneinfo.inc.php, and toner.inc.php (in includes/html/table).
Gravedad: Pendiente de análisis
Última modificación:
26/08/2026