Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-14932

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vulnerable to unauthenticated file read and deletion of image-extension files within the application directory.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/07/2026

CVE-2026-14586

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2 about monotonic timestamps could trigger and result in server termination and thus denial of service. When interfacing with libngtcp2, for DNS-over-QUIC support in Unbound, it is expected to use monotonic time. Unbound was using realtime instead, and in DoQ environments with high concurrency and under pressure, an assert in libngtcp2 for the quic timestamp would trigger and terminate the server.This vulnerability needs Unbound to be compiled with DoQ support ('--with-libngtcp2') and the 'quic-port' to be configured for the listening interfaces.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/07/2026

CVE-2026-16232

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
23/07/2026

CVE-2026-13185

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-13186

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-controlled input, enabling attacker-controlled deserialization and remote code execution.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-13187

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processing and enabling chained exploitation.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-13188

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potentially altering dialog server-side behavior and enabling chained exploitation.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/07/2026

CVE-2026-13189

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolution and trigger unintended server-side requests.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-13190

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-13192

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound network connections and potential exposure of Windows authentication credentials.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/07/2026

CVE-2026-13181

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affected deployments.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-13182

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026