Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-94245

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the user submitting a wallet transfer owns the wallet being debited, allowing any authenticated user, including one with only the Subscriber role, to move an arbitrary user's wallet balance, including an administrator's, into an account they control.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/10/2026

CVE-2026-94246

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the wallet account named in a withdrawal submission belongs to the user making it, allowing any authenticated user, such as a subscriber, to file a withdrawal request against another user's wallet for an amount and a payout destination of their choosing, and to indefinitely prevent that user from submitting withdrawals of their own.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/10/2026

CVE-2026-86828

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** The BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallback archive library is used, allowing high-privileged users to write files outside the intended restore directory, potentially leading to remote code execution.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/10/2026

CVE-2026-5769

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability in Brocade SANnav before 3.0.1 can have the Brocade Fabric OS switch admin password captured in plaintext within a memory swap file on the server hosting the Brocade SANnav Virtual Machine (VM). This can happen when the SANnav server encounters an Out Of Memory (OOM) condition. The vulnerability could allow an authenticated admin user with access to the server hosting the SANnav to potentially view the memory swap file and access the password(s).
Gravedad CVSS v4.0: MEDIA
Última modificación:
08/10/2026

CVE-2026-86826

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** The BackWPup WordPress plugin before 5.7.7 does not properly restrict web access to the working directory it uses during backup restores, allowing unauthenticated attackers, on webservers that do not honour .htaccess rules such as NGINX, to download the full backup archive (database dump and site files, including credentials and secret keys) left behind by an interrupted restore.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/10/2026

CVE-2026-86827

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** The BackWPup WordPress plugin before 5.7.7 does not verify that a request to its cron-triggered backup execution handler actually originates from WordPress's internal scheduled-event dispatch, allowing unauthenticated attackers to force any existing backup job to run immediately, independent of its configured trigger type or schedule.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/10/2026

CVE-2026-5048

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Brocade SANnav before 3.0.0a, an SQL Injection vulnerability in various external API inventories have a vulnerability that allows an authenticated attacker to inject malicious data into some of the REST API -query parameters.
Gravedad CVSS v4.0: MEDIA
Última modificación:
08/10/2026

CVE-2026-5049

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** A path traversal vulnerability affects the The Zone Alias Import flow feature in Brocade SANnav before 3.0.0a. A local authenticated attacker can write an uploaded content outside the intended directory.
Gravedad CVSS v4.0: MEDIA
Última modificación:
08/10/2026

CVE-2026-107459

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
08/10/2026

CVE-2026-5047

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability in Brocade SANnav before 2.4.0b and 3.0.0 prints encoded passwords and  authentication tokens in log files. The vulnerability could allow an authenticated attacker with access to the log file including the SANnav supportsave to access the passwords.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/10/2026

CVE-2026-105260

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Database Addon For WPForms ( wpforms entries ) WordPress plugin before 1.1.1 does not verify the CSRF nonce when the field is omitted and performs no capability check of its own, allowing attackers to delete arbitrary stored form entries by tricking a logged-in administrator into loading a crafted page.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/10/2026

CVE-2026-105195

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration.
Gravedad CVSS v3.1: BAJA
Última modificación:
08/10/2026