Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2025-51679

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected behavior.
Gravedad: Pendiente de análisis
Última modificación:
26/08/2026

CVE-2025-61478

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via Spoofed SYN packets.
Gravedad: Pendiente de análisis
Última modificación:
26/08/2026

CVE-2025-61479

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via the SPC Connect Pro software accepts replayed application-layer payloads injected into an active TCP session.
Gravedad: Pendiente de análisis
Última modificación:
26/08/2026

CVE-2025-61480

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP FIN packets without validating the sequence or acknowledgment numbers.
Gravedad: Pendiente de análisis
Última modificación:
26/08/2026

CVE-2026-79938

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Gravedad CVSS v3.1: ALTA
Última modificación:
26/08/2026

CVE-2026-79939

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Script injection.
Gravedad CVSS v3.1: MEDIA
Última modificación:
26/08/2026

CVE-2026-77652

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer.<br /> <br /> In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette with:<br /> <br /> ren-&gt;pPal = g_new0(WPGColorRGB, 256);<br /> <br /> When handling a WPG_COLORMAP record, the parser reads a start index (i16) and number of colors (iNum16) from the file and reads palette data with:<br /> <br /> bRet &amp;= (iNum16 == (int)fread(&amp;ren-&gt;pPal[i16], sizeof(WPGColorRGB), iNum16, f));<br /> <br /> The only bounds-related check is `if (i16 &gt;= 0 &amp;&amp; i16
Gravedad CVSS v3.1: ALTA
Última modificación:
26/08/2026

CVE-2026-77508

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account&amp;#39;s primary email through PUT or PATCH requests to /api/users/{username}/ without verifying the new address, allowing a later team invitation for that address to be accepted without access to the intended recipient&amp;#39;s mailbox. This issue is fixed in version 2026.8.
Gravedad CVSS v3.1: BAJA
Última modificación:
26/08/2026

CVE-2026-75601

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instances with both basic-auth and metrics features enabled process the /metrics endpoint before the basic-auth check in src/handler.rs, allowing an unauthenticated remote attacker to retrieve Prometheus metrics that disclose virtual host names, request volumes, error rates, latency distributions, and active connections. This issue is fixed in version 2.44.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
26/08/2026

CVE-2026-71172

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.
Gravedad CVSS v3.1: MEDIA
Última modificación:
26/08/2026

CVE-2026-74770

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command (&amp;#39;OS Command Injection&amp;#39;) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
Gravedad CVSS v3.1: ALTA
Última modificación:
26/08/2026

CVE-2026-74771

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.
Gravedad CVSS v3.1: MEDIA
Última modificación:
26/08/2026