Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-73102

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnerability in the macOS clipboard file-paste code path. The application accepts peer-supplied file descriptor names and joins them to the selected target directory without requiring normalized relative paths. A remote peer in an active clipboard file-paste session can use parent-directory components or absolute paths to write files outside the intended target directory at locations writable by the RustDesk process. Commit 6f1eb16 fixes the issue by validating descriptor names and safely joining paths.
Gravedad CVSS v4.0: MEDIA
Última modificación:
26/08/2026

CVE-2026-73108

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before authentication, the decoder trusts the payload length encoded in a four-byte frame header and reserves that amount before receiving the payload. A crafted header can request up to 1,073,741,823 bytes of capacity, allowing unauthenticated attackers to use concurrent TCP connections to cause memory exhaustion and denial of service. The fix caps header-triggered speculative preallocation at 256 KiB.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/08/2026

CVE-2026-3035

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with project Maintainer permissions could have accessed the terminal of a protected environment they were not authorized to use due to improper authorization checks.
Gravedad CVSS v3.1: MEDIA
Última modificación:
28/08/2026

CVE-2026-19271

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Neutralization of Special Elements used in an LDAP Query (&amp;#39;LDAP Injection&amp;#39;) vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows LDAP Injection.<br /> <br /> This issue affects Liderahenk: from 3.4.0 before 3.5.5.
Gravedad CVSS v3.1: ALTA
Última modificación:
26/08/2026

CVE-2026-18252

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source.
Gravedad CVSS v3.1: ALTA
Última modificación:
28/08/2026

CVE-2026-12717

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Service versions prior to 2026-05-01 on Google Cloud Platform allows an authenticated attacker to achieve remote code execution in the connector container and escalate privileges in the tenant project using crafted JDBC connection string parameters.<br /> <br /> <br /> This vulnerability was patched on 1 May 2026, and no customer action is needed.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
26/08/2026

CVE-2026-15990

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.0.1 via the &amp;#39;frm_graph&amp;#39; parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Successful exploitation requires Formidable Forms Lite, Formidable Forms Pro, and Formidable Charts to be active and requires the wp-content/uploads/frm-charts/ directory to exist, normally after an image-format chart is rendered.
Gravedad CVSS v3.1: ALTA
Última modificación:
27/08/2026

CVE-2026-15387

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have influenced the execution environment of Pipeline Execution Policy enforcement jobs, due to improper handling of job dependencies.
Gravedad CVSS v3.1: MEDIA
Última modificación:
28/08/2026

CVE-2025-10903

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have caused denial of service, due to an unbounded loop triggered by specially crafted input in the SCIM user provisioning feature.
Gravedad CVSS v3.1: MEDIA
Última modificación:
28/08/2026

CVE-2026-79619

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/08/2026

CVE-2026-77658

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A stack-based buffer overflow vulnerability exists in the Dia diagram editor when processing Network Bus objects from Dia XML project files.<br /> <br /> In objects/network/bus.c, bus_load() reads the number of bus handles from the file attribute "bus_handles" using attribute_num_data() without validating an upper bound:<br /> <br /> bus-&gt;num_handles = attribute_num_data(attr);<br /> <br /> When a bus handle is subsequently moved, bus_handle_moved() allocates two temporary arrays on the stack:<br /> <br /> parallel = (real *)g_alloca(num_handles * sizeof(real));<br /> perp = (real *)g_alloca(num_handles * sizeof(real));<br /> <br /> Because num_handles is fully attacker-controlled via the project file, sufficiently large values (for example 262144 or higher) cause g_alloca() to consume more stack space than the default thread stack limit (typically 8 MB on Linux), resulting in stack overflow, SIGSEGV, and potential stack frame / return-address corruption.<br /> <br /> An attacker can embed a Bus object with an excessive bus_handles count in a malicious .dia file. Exploitation requires the victim to open the file in Dia (file dialog, command line, or file association) and trigger handle manipulation (moving a bus handle), which exercises the vulnerable code path.<br /> <br /> The identical g_alloca pattern is present in objects/Misc/tree.c (copied from bus.c) and is likely vulnerable to the same class of attack via Tree objects.<br /> <br /> Affected versions: Dia 0.98.0 and earlier versions containing this code; issue confirmed on upstream master as of 2026-08-21.<br /> Upstream report: https://gitlab.gnome.org/GNOME/dia/-/issues/581
Gravedad CVSS v3.1: ALTA
Última modificación:
28/08/2026

CVE-2026-12587

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The vulnerability allows the unauthorised generation of physical access QR codes due to the use of hard-coded credentials within the application. The generation mechanism uses the &amp;#39;badge_number&amp;#39; parameter as the HMAC private key, the value of which remains static and is accessible via the API using the endpoint &amp;#39;/club/_id_club_/member/_id_member_/resamania_qr_info&amp;#39;. An attacker with access to this value and to the application’s cryptographic logic, which can be extracted by reverse engineering the APK as there is no code obfuscation, could generate valid QR codes indefinitely, even after the user has changed their password or logged out.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/08/2026