Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2025-67650

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks.<br /> This issue was fixed in the versions specified in the affected products list.
Gravedad CVSS v4.0: ALTA
Última modificación:
31/07/2026

CVE-2025-67651

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts.<br /> <br /> <br /> This issue was fixed in the versions specified in the affected products list.
Gravedad CVSS v4.0: MEDIA
Última modificación:
31/07/2026

CVE-2026-62391

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.<br /> <br /> This issue affects Apache Kyuubi: from 1.6.0 before 1.12.0.<br /> <br /> Users are recommended to upgrade to version 1.12.0, which fixes the issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
31/07/2026

CVE-2026-64607

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model.<br /> <br /> This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.
Gravedad CVSS v3.1: MEDIA
Última modificación:
31/07/2026

CVE-2026-44615

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a note, or access to folder operations, could supply traversal segments in note or folder paths.                   Zeppelin composed these values into filesystem paths using the server&amp;#39;s filesystem or Hadoop identity without ensuring that the result remained under the configured notebook directory. This could allow notebook files or directories to be moved,                   written, or deleted outside the notebook root. This issue affects Apache Zeppelin versions 0.9.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.
Gravedad CVSS v3.1: MEDIA
Última modificación:
31/07/2026

CVE-2026-16843

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.
Gravedad CVSS v3.1: ALTA
Última modificación:
31/07/2026

CVE-2026-17567

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.8 via the &amp;#39;transaction&amp;#39; parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to brute-force valid transaction hashes and view sensitive payment receipt data including customer name, email address, billing address, order items, payment method, and payment status belonging to other users. Because submission ID, form ID, and transaction creation time are either observable or guessable by an attacker, the effective brute-force space is bounded to approximately 900 candidates per second per (submission, form) pair, making exploitation practical without any prior authentication or account.
Gravedad CVSS v3.1: MEDIA
Última modificación:
01/08/2026

CVE-2026-18436

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign//restore-revision/). The route in the vulnerable range was registered without a permissionCallback, allowing the restoreRevision() handler to run for unauthenticated requests and overwrite a campaign&amp;#39;s content_html with any prior revision. This makes it possible for unauthenticated attackers to modify campaign content by restoring an arbitrary revision.
Gravedad CVSS v3.1: MEDIA
Última modificación:
31/07/2026

CVE-2026-18437

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The MailerPress – Newsletter, email marketing &amp; AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to update contact details.
Gravedad CVSS v3.1: MEDIA
Última modificación:
31/07/2026

CVE-2026-15722

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service.
Gravedad CVSS v3.1: ALTA
Última modificación:
31/07/2026

CVE-2026-11770

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.
Gravedad CVSS v3.1: ALTA
Última modificación:
01/08/2026

CVE-2026-10079

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causing ACS to treat the workload as having empty UID, name and labels and namespace "default". This bypasses deploy-time policy detection and enforcement visibility, prevents correct persistence in Central and breaks violation reporting and compliance correlation for the affected deployment.
Gravedad CVSS v3.1: ALTA
Última modificación:
31/07/2026