Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-78315

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to <br /> remote code execution.
Gravedad CVSS v3.1: ALTA
Última modificación:
24/08/2026

CVE-2026-78316

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to <br /> remote code execution.
Gravedad CVSS v3.1: ALTA
Última modificación:
24/08/2026

CVE-2026-78317

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to <br /> remote code execution.
Gravedad CVSS v3.1: ALTA
Última modificación:
24/08/2026

CVE-2026-75931

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative reference such as a host preceded by two slashes is returned with its host verbatim and no error set. As a result fast-uri&amp;#39;s own entry points disagree with each other: parse, resolve, normalize, and equal can yield different hosts for the same input depending only on whether a scheme is written out, and equal can return opposite verdicts for the same pair of hosts. An application that extracts a host with fast-uri to check it against a policy list and then resolves the same reference can make its decision on one host while the destination is another, enabling host confusion and policy bypass. The affected versions are 2.4.2 up to but not including 2.4.5, 3.1.3 up to but not including 3.1.6, and 4.0.1 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which canonicalize the host consistently across the resolve path. Users should upgrade to a patched version.
Gravedad CVSS v3.1: ALTA
Última modificación:
24/08/2026

CVE-2026-66897

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A path traversal vulnerability in LXD&amp;#39;s instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle but subsequently opens and creates the file using os.Create with an unconfined string path. This discrepancy between path resolution checks and file creation allows an attacker to escape directory confinement, overwrite root-owned host files, and achieve host root code execution.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
25/08/2026

CVE-2026-75899

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or resolve can turn nested percent-encoded input into a different network destination such as a loopback hostname or address. For example, a doubly encoded host that spells out a loopback name decodes to that live host in one operation, which contradicts RFC 3986 section 2.4 that an implementation must not decode the same string more than once. An application that normalizes or resolves an untrusted HTTP-family URI before outbound routing, redirect validation, or a host-policy check can receive a destination different from the one the original encoded host represented, giving a server-side request forgery and host-policy bypass primitive. This is an incomplete-fix variant of CVE-2026-6322. The affected versions are 2.4.1 up to but not including 2.4.5, 3.1.2 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which normalize percent escapes once and preserve encoded percent signs. Users should upgrade to a patched version.
Gravedad CVSS v3.1: ALTA
Última modificación:
24/08/2026

CVE-2026-16249

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rejected reason: This CVE ID is a duplicate of CVE-2026-15303 and was never published. Both IDs were assigned to the same vulnerability in the 6Storage Rentals WordPress plugin. All CVE users should reference CVE-2026-15303 instead of this ID.
Gravedad: Pendiente de análisis
Última modificación:
24/08/2026

CVE-2026-78306

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory country code, and wireless channel. An attacker can overwrite the Wi-Fi PSK with a known value and connect to the drone&amp;#39;s internal Wi-Fi network, potentially gaining access to the flight control interface and issuing flight commands. Crafted DUML commands can also disable or restart the Wi-Fi and Bluetooth interfaces, disconnect Wi-Fi clients, or reset wireless configuration, resulting in a denial-of-service condition that can disrupt the operator&amp;#39;s wireless control, video, and telemetry connections during flight.<br /> <br /> Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600.<br /> <br /> <br /> Remediation requires a firmware update from the vendor.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/08/2026

CVE-2026-78321

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access to the drone&amp;#39;s internal network can exhaust the server&amp;#39;s connection pool by repeatedly requesting a stored media file, preventing the server from handling legitimate requests and causing a denial of service that prevents the DJI Fly application from retrieving photos and videos from the aircraft in QuickTransfer mode.<br /> <br /> Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600.<br /> <br /> Remediation requires a firmware update from the vendor.
Gravedad CVSS v4.0: MEDIA
Última modificación:
24/08/2026

CVE-2026-77993

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK
Gravedad CVSS v4.0: MEDIA
Última modificación:
24/08/2026

CVE-2026-77994

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
24/08/2026

CVE-2026-78255

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authenticating the requesting client. Filenames follow a predictable pattern, allowing an attacker who joins the drone&amp;#39;s internal network to enumerate valid filenames and exfiltrate stored photos and videos. The exposed media may reveal sensitive information, including private locations, property, travel history, identifiable individuals, and the operator&amp;#39;s routines.<br /> <br /> Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/08/2026