Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-18603

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ownership checks when adding the contents of a previous order to the cart, allowing unauthenticated users to disclose the contents of other customers' orders, as well as to clear and repopulate a logged in user's cart via a crafted link.
Gravedad: Pendiente de análisis
Última modificación:
09/08/2026

CVE-2026-18465

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not properly validate a user-controlled path before using it in a file inclusion, allowing unauthenticated attackers to include and execute arbitrary existing local PHP files on the server.
Gravedad: Pendiente de análisis
Última modificación:
09/08/2026

CVE-2026-18473

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
Gravedad: Pendiente de análisis
Última modificación:
09/08/2026

CVE-2026-18357

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allowing unauthenticated attackers to retrieve sensitive order data belonging to any customer of the store, such as billing names, order IDs and statuses, fee amounts and order dates.
Gravedad: Pendiente de análisis
Última modificación:
09/08/2026

CVE-2026-18464

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated attackers to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service.
Gravedad: Pendiente de análisis
Última modificación:
09/08/2026

CVE-2026-18037

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its public REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available.
Gravedad: Pendiente de análisis
Última modificación:
09/08/2026

CVE-2026-17044

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users.
Gravedad: Pendiente de análisis
Última modificación:
09/08/2026

CVE-2026-18032

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the nonce guarding that action does not cover them, allowing unauthenticated attackers to read arbitrary columns of the database table the affected front-end form is bound to, including user password hashes where that table is the users table.
Gravedad: Pendiente de análisis
Última modificación:
09/08/2026

CVE-2026-17014

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores.
Gravedad: Pendiente de análisis
Última modificación:
09/08/2026

CVE-2026-17017

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX action, and does not include a capability check on that action, allowing users with Subscriber-level access and above to perform SQL injection attacks.
Gravedad: Pendiente de análisis
Última modificación:
09/08/2026

CVE-2026-16992

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available.
Gravedad: Pendiente de análisis
Última modificación:
09/08/2026

CVE-2026-17011

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing.
Gravedad: Pendiente de análisis
Última modificación:
09/08/2026