Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-82550

Fecha de publicación:
30/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component NGSetupRequest Handler. Performing a manipulation of the argument NG-IoT-DefaultPagingDRX results in improper input validation. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Gravedad CVSS v4.0: MEDIA
Última modificación:
30/08/2026

CVE-2026-78699

Fecha de publicación:
30/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that collides with an existing tenant&amp;#39;s schema to have their tenant record repointed at that other tenant&amp;#39;s live schema, gaining access to its data.<br /> <br /> AshPostgres.MultiTenancy.rename_tenant/3 issues the ALTER SCHEMA ... RENAME TO ... with the non-raising Ecto.Adapters.SQL.query/2, discards its {:ok, _} | {:error, _} result, and unconditionally returns :ok. PostgreSQL rejects the rename when the target schema already exists (and on insufficient privilege or lock timeout), but that failure never reaches the caller. The calling manage_tenant update action therefore sees success and commits the tenant row with the new name, which is the schema of a different existing tenant, so subsequent reads and writes for that tenant run against the other tenant&amp;#39;s data.<br /> <br /> This issue affects ash_postgres: from 0.25.0 before 2.13.0.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/08/2026

CVE-2026-82655

Fecha de publicación:
30/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can bypass authentication by providing a dummy UUID in role_list and inject SQL through relation_type_list to extract database contents including password hashes and user credentials.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/08/2026

CVE-2026-82656

Fecha de publicación:
30/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality, allowing authenticated users with album-creation rights to include path traversal segments in archive entry names. Attackers can craft malicious album names containing directory traversal sequences that escape the intended directory when recipients extract the archive, potentially writing files outside the target directory.
Gravedad CVSS v4.0: BAJA
Última modificación:
30/08/2026

CVE-2026-82657

Fecha de publicación:
30/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve forum topics and announcements by sending GET requests to rss/forum.php or rss/announcements.php, disclosing titles, full post text, author names, and timestamps.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/08/2026

CVE-2026-82653

Fecha de publicación:
30/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with HTML/script payloads in the name field that execute in users&amp;#39; browsers when uninstalling packages or unlocking encrypted notebooks.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
30/08/2026

CVE-2026-82654

Fecha de publicación:
30/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block&amp;#39;s name to contain HTML/script tags that execute when another user views documents referencing or displaying that block.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
30/08/2026

CVE-2026-82658

Fecha de publicación:
30/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read another user&amp;#39;s future role memberships. Attackers can bypass profile-level authorization by directly calling the reload_future_memberships endpoint with a victim&amp;#39;s user UUID to disclose sensitive membership information.
Gravedad CVSS v4.0: MEDIA
Última modificación:
30/08/2026

CVE-2026-82646

Fecha de publicación:
30/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** WWBN AVideo contains an unauthenticated reflected cross-site scripting vulnerability in the url2Embed.json.php endpoint that allows attackers to inject malicious scripts by supplying URLs with HTML metacharacters. Attackers can mint an encrypted evideo payload containing unescaped markup, then deliver it as a legitimate-looking link on the site&amp;#39;s own domain to execute JavaScript in victims&amp;#39; sessions and steal cookies or CSRF tokens.
Gravedad CVSS v4.0: MEDIA
Última modificación:
30/08/2026

CVE-2026-82647

Fecha de publicación:
30/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrators to send mail from the site&amp;#39;s contact address by bypassing origin checks and captcha validation. Attackers can craft a malicious web page that, when visited by an authenticated admin, sends emails with attacker-controlled subject and body to arbitrary recipients, passing SPF/DKIM/DMARC validation for phishing and brand impersonation attacks.
Gravedad CVSS v4.0: MEDIA
Última modificación:
30/08/2026

CVE-2026-82650

Fecha de publicación:
30/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the RenderTemplate function (kernel/model/template.go), reachable via the POST /api/template/render endpoint (kernel/api/template.go). The endpoint restricts the supplied path only to the workspace directory (util.IsAbsPathInWorkspace) but, unlike the file API&amp;#39;s refuseToAccess() blocklist, applies no sensitive-path exclusion. This allows an authenticated attacker to read sensitive workspace files, including conf/conf.json, which contains the API token and cookie signing key. The issue is fixed in v3.8.1.
Gravedad CVSS v4.0: MEDIA
Última modificación:
30/08/2026

CVE-2026-82651

Fecha de publicación:
30/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*path and /repo/diff/*path endpoints in kernel/server/serve.go. These routes require admin authentication but construct file paths independently, so an authenticated administrator can retrieve historical snapshots of sensitive files that the guard is meant to block, including data/.siyuan/publishAccess.json (plaintext publish-mode passwords) and files under data/templates/.
Gravedad CVSS v4.0: MEDIA
Última modificación:
30/08/2026