Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-4245

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.11. This is due to the `duplicate_post_permissions()` permission callback only verifying the `duplicate_posts` capability without checking whether the requesting user holds `publish_posts` or other status-gated capabilities. This makes it possible for authenticated attackers, with Contributor-level access and above, to create duplicate posts with `future` (scheduled, auto-publishes) or `private` status, bypassing editorial review. Additionally, the REST endpoint does not enforce administrator-configured post-type duplication restrictions, allowing duplication of post types that have been explicitly disabled.
Gravedad CVSS v3.1: MEDIA
Última modificación:
24/08/2026

CVE-2026-66916

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery
Gravedad CVSS v4.0: MEDIA
Última modificación:
22/08/2026

CVE-2026-3424

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10.3. This is due to the software allowing users to execute an action that does not properly validate the 'payload' value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Gravedad CVSS v3.1: MEDIA
Última modificación:
24/08/2026

CVE-2026-77946

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulation of the argument system.ntp.server/system.ntp.enable_server/cameo.time.time_zone/cameo.cameo.syslog_server can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
24/08/2026

CVE-2026-77945

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown function of the file /cgi-bin/upload.cgi of the component ssi. Performing a manipulation of the argument filename results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used.
Gravedad CVSS v4.0: BAJA
Última modificación:
24/08/2026

CVE-2026-12710

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data.<br /> <br /> <br /> <br /> <br /> The issue was patched on April 4, 2026; no customer action is required.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
22/08/2026

CVE-2026-78003

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from $_POST[&amp;#39;addresses&amp;#39;], passes them through sanitize_text_field(). This makes it possible for unauthenticated attackers to make authenticated POST requests to any Mailgun API endpoint using the WordPress site&amp;#39;s API key, including creating inbound email-forwarding routes that can intercept password reset emails, leading to administrator account takeover.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
24/08/2026

CVE-2026-77000

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by supplying that user&amp;#39;s email address.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
23/08/2026

CVE-2026-77001

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Social Login &amp; Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any existing user, including administrators. In the default case a session as the site&amp;#39;s original administrator account is obtained without needing to know any account details at all.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
23/08/2026

CVE-2026-77002

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
23/08/2026

CVE-2026-19221

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/08/2026

CVE-2026-19222

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/08/2026