Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-76600

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in Fabrik
Gravedad CVSS v4.0: MEDIA
Última modificación:
24/08/2026

CVE-2026-76571

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
24/08/2026

CVE-2026-76599

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in Fabrik
Gravedad CVSS v4.0: ALTA
Última modificación:
24/08/2026

CVE-2026-70626

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root. The vulnerability exists because path validation is lexical and does not account for symlink resolution, enabling attackers to place symlinks inside the corpus root to access files outside the intended boundary.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/08/2026

CVE-2026-6258

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Gravedad: Pendiente de análisis
Última modificación:
22/08/2026

CVE-2026-74584

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> RDMA/bnxt_re: zero shared page before exposing to userspace<br /> <br /> bnxt_re_alloc_ucontext() allocates uctx-&gt;shpg via<br /> __get_free_page(GFP_KERNEL). The buddy allocator does not zero pages<br /> without __GFP_ZERO, so the page contains stale kernel data from<br /> whatever object most recently freed it.<br /> <br /> The page is then mapped into userspace via vm_insert_page() under<br /> BNXT_RE_MMAP_SH_PAGE in bnxt_re_mmap(). The driver only ever writes<br /> 4 bytes (a u32 AVID) at offset BNXT_RE_AVID_OFFT (0x10) inside<br /> bnxt_re_create_ah(); the remaining 4092 bytes of the page are exposed<br /> to userspace unsanitised, leaking kernel memory contents.<br /> <br /> Any user with access to /dev/infiniband/uverbsX on a host with a<br /> bnxt_re device (typically rdma group membership) can read this data<br /> via a single mmap() at pgoff 0 after IB_USER_VERBS_CMD_GET_CONTEXT.<br /> <br /> Other shared pages in the same file already use get_zeroed_page()<br /> correctly:<br /> <br /> drivers/infiniband/hw/bnxt_re/ib_verbs.c<br /> srq-&gt;uctx_srq_page = (void *)get_zeroed_page(GFP_KERNEL);<br /> cq-&gt;uctx_cq_page = (void *)get_zeroed_page(GFP_KERNEL);<br /> <br /> uctx-&gt;shpg is the only outlier. Bring it in line with the existing<br /> convention by switching to get_zeroed_page().
Gravedad: Pendiente de análisis
Última modificación:
22/08/2026

CVE-2026-68766

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files with malicious options to append attacker-controlled content to arbitrary files, enabling code execution when targeting shell startup files.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/08/2026

CVE-2026-68768

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function in src/outfile.c. When assembling output into a fixed-size buffer (HCBUFSIZ_LARGE, ~16 MB), the function sequentially appends the username, separator, hash, and plaintext via memcpy without validating that the accumulated length stays within the buffer capacity. When run with --username --show against a crafted hash file containing an oversized username that nearly fills the buffer, the total assembled output exceeds the buffer, causing a heap buffer overflow that can corrupt memory and crash the process.
Gravedad CVSS v4.0: MEDIA
Última modificación:
24/08/2026

CVE-2026-68767

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** hashcat&amp;#39;s fgetl() function in src/filehandling.c writes a null terminator one byte past the caller&amp;#39;s buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wordlist containing a line of exactly HCBUFSIZ_LARGE bytes.
Gravedad CVSS v4.0: MEDIA
Última modificación:
22/08/2026

CVE-2026-63312

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of the ENFORCE setting, including sensitive system files and application credentials.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/08/2026

CVE-2026-63310

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
24/08/2026

CVE-2026-65915

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file:// URLs to nltk.data.load() to read arbitrary files accessible to the process user, including credentials and configuration files.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/08/2026