Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-57998

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then passes that string to child_process.exec() in index.ts, which spawns a shell. A registry value containing shell metacharacters such as a semicolon, pipe, or command substitution executes arbitrary operating system commands with the privileges of the process running the audit.
Gravedad CVSS v4.0: ALTA
Última modificación:
22/08/2026

CVE-2026-58001

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in objects/videoEditLight.php that lacks request authenticity checks and accepts GET requests. Attackers can store an img tag in a video description that transfers video ownership to an attacker-controlled account when an administrator views the video page.
Gravedad CVSS v4.0: MEDIA
Última modificación:
22/08/2026

CVE-2026-59256

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. Attackers can retrieve a token from the Gallery endpoint and use it to bypass authorization checks in other subsystems like view/hls.php to access restricted video content.
Gravedad CVSS v4.0: ALTA
Última modificación:
22/08/2026

CVE-2026-58002

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an authorization bypass vulnerability in the Users_affiliations add.json.php endpoint that allows authenticated users to forge two-party consent records by supplying the counterparty's agreement timestamp. Attackers can create a forged affiliation with status='a' and then reassign video ownership to arbitrary users through the videoAddNew.json.php endpoint, which trusts the forged affiliation as an authorization term.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/08/2026

CVE-2026-58003

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php endpoint that lacks authenticity checks and accepts GET requests. Attackers can craft a malicious cross-site GET request carrying an administrator's session cookie to permanently publish any embargoed video by manipulating the videos_id parameter.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/08/2026

CVE-2026-59808

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogin() converts this hash into passwordless login as the video owner. Attackers with upload permission can retrieve an administrator's video_id_hash by omitting the videos_id parameter, then use that hash in an unauthenticated request to gain administrative session access and modify system configuration.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/08/2026

CVE-2026-11948

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Gravedad: Pendiente de análisis
Última modificación:
22/08/2026

CVE-2026-4244

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `duplicate_post()` function in all versions up to, and including, 3.0.11. This is due to the function not verifying that the user has `edit_others_posts` capability before accepting a `selectedAuthorId` parameter via the `duplicate-post` REST endpoint. This makes it possible for authenticated attackers, with Contributor-level access and above, to create duplicated posts attributed to any user, including administrators.
Gravedad CVSS v3.1: MEDIA
Última modificación:
24/08/2026

CVE-2026-56380

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthenticated attackers to retrieve channel owner email addresses by supplying a public channel name parameter. Attackers can enumerate all creator email addresses by iterating through public channel names and extract them from the itunes:email and itunes:author RSS elements, enabling account takeover attempts and phishing campaigns.
Gravedad CVSS v4.0: MEDIA
Última modificación:
24/08/2026

CVE-2026-11947

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Gravedad: Pendiente de análisis
Última modificación:
22/08/2026

CVE-2026-66916

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery
Gravedad CVSS v4.0: MEDIA
Última modificación:
22/08/2026

CVE-2026-66917

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery
Gravedad CVSS v4.0: ALTA
Última modificación:
24/08/2026