Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-55497

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed file size but do not limit decoded pixel dimensions, allowing an authenticated user to submit a small PNG, JPEG, or GIF that triggers an unbounded allocation and terminates the Cloudreve process through fatal out-of-memory behavior. This issue is fixed in version 4.17.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
31/07/2026

CVE-2026-55495

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than a filename, allowing slash and dot-dot segments to escape the source file directory and create or conditionally overwrite files elsewhere in the same owner account. This issue is fixed in version 4.17.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
31/07/2026

CVE-2026-43832

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Full details and mitigation steps are currently restricted and will be published at a later date.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
31/07/2026

CVE-2026-43833

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Full details and mitigation steps are currently restricted and will be published at a later date.
Gravedad CVSS v4.0: ALTA
Última modificación:
31/07/2026

CVE-2026-55496

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActive without adding a StatusActive predicate and serializes matches at RedactLevelUser, allowing any logged-in user to enumerate email addresses and profile metadata for inactive or banned accounts. The service calls userClient.SearchActive, but despite its name that method filters only by email/nickname keyword and never adds a StatusActive predicate — while the sibling lookups GetActiveByID and GetActiveByDavAccount, defined a few lines above it, do. Search hits are serialized at RedactLevelUser, which includes the email address. This issue is fixed in version 4.17.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
31/07/2026

CVE-2026-43830

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Full details and mitigation steps are currently restricted and will be published at a later date.
Gravedad CVSS v4.0: ALTA
Última modificación:
31/07/2026

CVE-2026-43831

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Full details and mitigation steps are currently restricted and will be published at a later date.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
31/07/2026

CVE-2026-43829

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Full details and mitigation steps are currently restricted and will be published at a later date.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
31/07/2026

CVE-2026-6889

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Gravedad: Pendiente de análisis
Última modificación:
31/07/2026

CVE-2026-6890

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Gravedad: Pendiente de análisis
Última modificación:
31/07/2026

CVE-2026-18157

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful exploitation could lead to remote code execution (RCE) with root privileges, enabling the attacker to fully compromise the system's integrity, confidentiality, and availability.
Gravedad CVSS v3.1: ALTA
Última modificación:
31/07/2026

CVE-2026-14541

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience or clientId, the ValidateMCPAuth pipeline for opaque tokens skips audience validation entirely. As a result, the toolbox will accept any valid Google OAuth access token—even those minted for unrelated ecosystem applications—granting unauthorized clients access to protected tools and data backends.
Gravedad CVSS v4.0: ALTA
Última modificación:
31/07/2026