Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-59912

Fecha de publicación:
03/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and arbitrary code execution.
Gravedad CVSS v3.1: ALTA
Última modificación:
03/08/2026

CVE-2026-59913

Fecha de publicación:
03/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Gravedad CVSS v3.1: ALTA
Última modificación:
03/08/2026

CVE-2026-38444

Fecha de publicación:
03/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is extracted without sanitization in include/class.mailparse.php and stored raw in the poster field of ost_thread_entry. When an unauthenticated attacker sends a reply email to an existing ticket from an unregistered address with an XSS payload in the From display name.
Gravedad CVSS v3.1: MEDIA
Última modificación:
03/08/2026

CVE-2026-38446

Fecha de publicación:
03/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread entry title field. User-controlled input in the title is stored without adequate HTML escaping and later rendered in multiple staff-facing templates without proper output encoding. An attacker can inject arbitrary JavaScript by submitting a crafted ticket reply or email with a malicious subject line.
Gravedad CVSS v3.1: MEDIA
Última modificación:
03/08/2026

CVE-2026-38447

Fecha de publicación:
03/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and brute-force the key space within a feasible time window.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
03/08/2026

CVE-2026-18614

Fecha de publicación:
03/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Gravedad CVSS v4.0: ALTA
Última modificación:
03/08/2026

CVE-2026-18616

Fecha de publicación:
03/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the component wg-server.so Native Plugin. The manipulation of the argument public_key leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Gravedad CVSS v4.0: ALTA
Última modificación:
03/08/2026

CVE-2026-18615

Fecha de publicación:
03/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-bin/glc of the component wg-server.so Native Plugin. Executing a manipulation of the argument private_key can lead to command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Gravedad CVSS v4.0: ALTA
Última modificación:
03/08/2026

CVE-2025-15631

Fecha de publicación:
03/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A<br /> cryptographic weakness exists in affected Omada devices where site credentials<br /> are protected using a legacy hashing algorithm that does not provide sufficient<br /> protection.<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> An attacker<br /> who obtains access to stored credential data may be able to recover valid credentials<br /> to gain unauthorized access to affected devices or management environments.
Gravedad CVSS v4.0: MEDIA
Última modificación:
03/08/2026

CVE-2025-15627

Fecha de publicación:
03/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A cryptographic<br /> weakness exists in the Omada adoption protocol. <br /> The protocol relies on hard-coded cryptographic keys to establish trust and<br /> protect authentication exchanges between controllers and managed devices during<br /> device adoption.<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> An attacker may<br /> be able to impersonate trusted controllers or managed devices and gain access<br /> to sensitive adoption-related communications.
Gravedad CVSS v4.0: MEDIA
Última modificación:
03/08/2026

CVE-2025-15628

Fecha de publicación:
03/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Affected<br /> Omada devices rely on embedded certificates that are shared across deployments<br /> to establish trust between controllers and managed devices.<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> An attacker<br /> who obtains the embedded certificates may be able to impersonate trusted<br /> controllers or devices and intercept affected communications.
Gravedad CVSS v4.0: ALTA
Última modificación:
03/08/2026

CVE-2025-15629

Fecha de publicación:
03/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A cryptographic<br /> weakness exists in the Omada adoption protocol where session encryption keys<br /> used to protect communications between controllers and managed devices may be<br /> predictable due to insufficient entropy in session key generation.<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> An attacker<br /> who successfully intercepts adoption-related communications may be able to recover<br /> session encryption keys and decrypt affected communications.
Gravedad CVSS v4.0: MEDIA
Última modificación:
03/08/2026