Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-13189

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolution and trigger unintended server-side requests.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-13190

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-13192

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound network connections and potential exposure of Windows authentication credentials.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/07/2026

CVE-2026-13181

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affected deployments.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-13182

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-13183

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-13184

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-8152

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack.<br /> <br /> <br /> When Unblu Spark is deployed with com.unblu.identifier.siteEmbeddedSetup=true, it runs in the same origin as the host application. Any JavaScript injected through this vulnerability therefore executes with full access to the host application&amp;#39;s cookies, DOM, and same-origin APIs — an attacker can reach all resources of the host application, not just Unblu&amp;#39;s. This expanded blast radius is the reason on-premises deployments using this configuration are rated CRITICAL.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
22/07/2026

CVE-2026-44191

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts settings, allowing an attacker to inject shell separators. This can be triggered automatically during Language Server initialization or manually when executing a playbook. Successful exploitation leads to remote code execution (RCE) on the victim&amp;#39;s machine with the privileges of the Visual Studio Code user, potentially resulting in a complete system compromise.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-16270

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule can add an unsafe regex to a field. When someone provide the proper string it can result in a DoS attack.<br /> <br /> <br /> This issue was fixed in version 0.6.4.
Gravedad CVSS v4.0: MEDIA
Última modificación:
22/07/2026

CVE-2026-65603

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Grav Login plugin (grav-plugin-login) versions
Gravedad CVSS v4.0: ALTA
Última modificación:
22/07/2026

CVE-2026-65598

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node&amp;#39;s clone operation that allows authenticated users to bypass path restrictions by swapping a directory for a symlink after the path is validated but before the clone runs. This lets an attacker plant a crafted repository in the community node directory, which n8n loads as a custom node on the next restart, executing arbitrary JavaScript on the server. Both self-hosted and cloud instances are affected.
Gravedad CVSS v4.0: ALTA
Última modificación:
22/07/2026