Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-16573

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing unauthenticated attackers to upload a crafted SVG file containing JavaScript that executes when the file is viewed, leading to Stored Cross-Site Scripting.
Gravedad: Pendiente de análisis
Última modificación:
05/08/2026

CVE-2026-16583

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8 does not sanitize uploaded SVG files when its SVG upload feature is enabled, allowing authenticated users with the upload capability (Author and above by default, without the unfiltered_html capability) to upload SVG files containing JavaScript that executes in the site context when the file is viewed, leading to Stored Cross-Site Scripting.
Gravedad: Pendiente de análisis
Última modificación:
05/08/2026

CVE-2026-16602

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an unauthenticated REST endpoint, allowing unauthenticated users to disclose the content of non-public (draft, private, and pending) posts on sites that have a captcha provider configured.
Gravedad: Pendiente de análisis
Última modificación:
05/08/2026

CVE-2026-14553

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied content type and preserving the original file extension, allowing any authenticated user (Subscriber or higher) to upload arbitrary PHP files and achieve remote code execution.
Gravedad: Pendiente de análisis
Última modificación:
05/08/2026

CVE-2026-15210

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.
Gravedad: Pendiente de análisis
Última modificación:
05/08/2026

CVE-2025-15677

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in a multisite setup).
Gravedad: Pendiente de análisis
Última modificación:
05/08/2026

CVE-2026-71190

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic backtracking (ReDoS). The "qdtext" pattern (?:[^"]|\\.)* allows an unauthenticated remote attacker to send a crafted Accept header that causes exponential CPU consumption in the proxy worker. A payload of 32 backslash-character pairs exceeds 30 seconds of CPU time. No authentication is required. Repeated requests can exhaust all proxy worker threads, resulting in a complete denial of service.
Gravedad CVSS v4.0: ALTA
Última modificación:
05/08/2026

CVE-2026-71191

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration.
Gravedad CVSS v4.0: MEDIA
Última modificación:
05/08/2026

CVE-2026-71192

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An<br /> attacker can inject these headers into a signed PUT request targeting their own bucket, causing Swift to perform a server-side copy from another tenant&amp;#39;s private object. The source object authorization is bypassed because the S3API middleware has already authorized the request against the destination. The attacker can read any object whose project_id, container name, and object name are known, regardless of the source object&amp;#39;s ACLs or ownership. This requires the non-default s3_acl=true configuration.
Gravedad CVSS v4.0: MEDIA
Última modificación:
05/08/2026

CVE-2026-7753

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing capability check on the `cost-calculator-custom-export-run` AJAX action (handler `CCBExportImport::export_calculators()`) in all versions up to, and including, 3.6.17. The handler only verifies a nonce, but the corresponding `ccb_export_nonce` is broadcast on every wp-admin page (including pages reachable to Subscribers, such as `/wp-admin/profile.php`) by the `ccb_add_admin_nonces` callback hooked to `admin_head`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export every calculator&amp;#39;s full configuration — including stored Stripe secret keys, PayPal client secrets, Razorpay secret keys, webhook secret keys, and reCAPTCHA secret keys.
Gravedad CVSS v3.1: MEDIA
Última modificación:
05/08/2026

CVE-2026-8761

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is due to a missing authorization check in the `CustomersController` REST controller (`includes/REST/CustomersController.php`), which re-registers WooCommerce&amp;#39;s customer CRUD routes under the `/dokan/v1/customers/` namespace and replaces WooCommerce&amp;#39;s native `manage_woocommerce` capability check with a vendor-only check that inspects the **requesting** user&amp;#39;s role and never validates the **target** user. This makes it possible for authenticated attackers with Vendor/Seller-level access and above to read, modify, or delete any WordPress user — including administrators — via `GET`/`PUT`/`DELETE` requests against `/wp-json/dokan/v1/customers/{id}`. Setting the `password` parameter on an administrator&amp;#39;s record yields a full site takeover.
Gravedad CVSS v3.1: ALTA
Última modificación:
05/08/2026

CVE-2026-8790

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST parameter of the Shoutbox widget in all versions up to, and including, 2.13.4 due to insufficient input sanitization and output escaping. When a shoutbox form submission fails the nonce check (or `shouttext` is empty, or the user is unable to save), the raw POST value is echoed back into a `` element using `printf(&amp;#39;%s&amp;#39;, ...)` with no HTML escaping. This makes it possible for unauthenticated attackers to execute arbitrary web scripts in the browser of an authenticated victim (Subscriber-level or higher) who is tricked into submitting a crafted POST request to a page that contains the Shoutbox widget.
Gravedad CVSS v3.1: MEDIA
Última modificación:
05/08/2026