Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-63234

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A SQL injection and unsafe deserialisation<br /> vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark<br /> assessment endpoint, control data passed to unserialize(), write a webshell to<br /> a publicly accessible location, and execute arbitrary code on the server.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
29/07/2026

CVE-2026-14234

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowing an unauthenticated attacker to trick a logged-in administrator into writing arbitrary content, including a malicious script, into a post via a cross-site request, resulting in stored Cross-Site Scripting.
Gravedad: Pendiente de análisis
Última modificación:
29/07/2026

CVE-2026-14300

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers to obtain a valid session for any account, including administrators, by requesting a code for an email address they control and replaying it against the victim&amp;#39;s email address. Exploitation requires the Profile Completion feature to be enabled and social login to be configured.
Gravedad: Pendiente de análisis
Última modificación:
29/07/2026

CVE-2026-11974

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The wp-media-folder-addon WordPress plugin through 4.1.6 does not validate a user-supplied parameter before using it in a file read operation in two AJAX actions available to unauthenticated users, leading to Arbitrary File Disclosure and Server-Side Request Forgery on sites where a cloud storage connection has been configured. This is an incomplete fix of CVE-2026-9690, whose patch hardened only one of the affected cloud-storage handlers and left the others unpatched.
Gravedad CVSS v3.1: ALTA
Última modificación:
29/07/2026

CVE-2026-13423

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which invokes an attacker-supplied PHP function with an attacker-supplied argument array, allowing unauthenticated attackers to call arbitrary functions (for example to create an administrator account), leading to privilege escalation and remote code execution.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
29/07/2026

CVE-2026-13605

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into the page DOM without escaping. Because the title attribute survives the post-content sanitization applied to users who lack the unfiltered_html capability, an authenticated user with Author-level access can store a JavaScript payload that executes in the browser of any visitor, including an administrator, who clicks the link.
Gravedad CVSS v3.1: MEDIA
Última modificación:
29/07/2026

CVE-2026-13690

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user&amp;#39;s credentials to bypass the second authentication factor and log in as that user.
Gravedad CVSS v3.1: ALTA
Última modificación:
29/07/2026

CVE-2026-13692

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The PayU CommercePro Plugin WordPress plugin through 3.8.9 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders.
Gravedad CVSS v3.1: MEDIA
Última modificación:
29/07/2026

CVE-2026-14224

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Easy Appointments WordPress plugin through 3.12.26 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any authenticated user can obtain from their own appointment&amp;#39;s edit form. A subscriber-level user with an appointment of their own can therefore reuse that nonce to overwrite the customer metadata (email, name, phone, description) of another user&amp;#39;s appointment. Because the Easy Appointments WordPress plugin through 3.12.26 then treats that metadata as the appointment&amp;#39;s contact data, a subsequent administrator status change with customer notifications enabled delivers the victim&amp;#39;s appointment notification to the attacker-controlled email address.
Gravedad CVSS v3.1: MEDIA
Última modificación:
29/07/2026

CVE-2026-63227

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An unrestricted SCORM file upload vulnerability<br /> in Koollab LMS allowed<br /> an authenticated module designer to upload a SCORM package containing a PHP<br /> webshell to a publicly accessible directory and execute arbitrary code on the<br /> server.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
29/07/2026

CVE-2026-11351

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API endpoints, allowing unauthenticated users to retrieve information about non-published (e.g. draft, pending or private) WooCommerce products.
Gravedad CVSS v3.1: MEDIA
Última modificación:
29/07/2026

CVE-2026-18072

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function — registered on WordPress&amp;#39;s `init` hook at priority 1 so that it runs before any authentication checks on every request — reads an attacker-supplied token from the `_wplogin` (or `_wpm`) parameter and compares it against a hardcoded SHA-256 hash embedded directly in the plugin source, with no nonce verification, no capability check, and no password validation anywhere in the flow. Because this static hash constitutes a set of universal credentials that are publicly accessible in the plugin&amp;#39;s source code, unauthenticated attackers can supply the known token to be authenticated as an arbitrarily selected existing administrator account, gaining full administrative control over the affected WordPress site. This was likely introduced by an attacker who gained commit access to the developers account.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
29/07/2026