Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-16263

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to include and execute arbitrary existing local PHP files on the server.
Gravedad CVSS v3.1: ALTA
Última modificación:
07/08/2026

CVE-2026-16265

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not restrict the operation it dispatches, allowing users with a Subscriber account to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2026-19196

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the file /social/ajax.php?action=login. The manipulation of the argument email results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
Gravedad CVSS v4.0: MEDIA
Última modificación:
07/08/2026

CVE-2026-15032

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an HTML attribute, allowing unauthenticated users to store a Cross-Site Scripting payload that executes in the browser of any user, including administrators, who views the affected content.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2026-15214

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any authenticated customer to read another customer's subscription information (the subscribed product, status, and dates) by supplying that subscription's ID.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2026-15359

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allowing unauthenticated attackers to overwrite the administrator's stored cloud service connection with an account under their control, disconnecting the legitimate administrator and redirecting the site's cloud template library to attacker-controlled content.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2026-16030

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts.
Gravedad CVSS v3.1: ALTA
Última modificación:
07/08/2026

CVE-2026-15215

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) to install and activate arbitrary Subscriptions for WooCommerce WordPress plugin before 2.0.1, resulting in remote code execution.
Gravedad CVSS v3.1: ALTA
Última modificación:
07/08/2026

CVE-2026-15245

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript context before echoing it into an inline script, allowing users with the contributor role and above to inject arbitrary JavaScript that executes in the browser of anyone viewing the affected content.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2026-15361

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection attacks.
Gravedad CVSS v3.1: ALTA
Última modificación:
07/08/2026

CVE-2026-15386

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an attribute of the link it builds for linked galleries, allowing users with the Author role or above to store a JavaScript payload that executes in the browser of any visitor (including administrators) who views a post containing such a gallery.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2026-16038

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
07/08/2026