Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-94258

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** The SMS Alert WordPress plugin before 4.0.1 does not check that the acting administrator is allowed to manage the selected users before returning their stored billing phone numbers, allowing an administrator of one site on a multisite network to disclose the phone numbers of users who belong to other sites on that network.<br /> This affects multisite only, and requires the SMS Alert WordPress plugin before 4.0.1&amp;#39;s gateway credentials to be stored on the acting administrator&amp;#39;s own site.
Gravedad CVSS v3.1: BAJA
Última modificación:
08/10/2026

CVE-2026-94275

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Track Orders for WooCommerce WordPress plugin before 1.2.7 does not verify ownership of an order before returning its billing details, allowing unauthenticated attackers to obtain a customer&amp;#39;s name, email address, phone number, postal address and order history by supplying that customer&amp;#39;s email address.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/10/2026

CVE-2026-94244

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not perform any capability check, and relies on a token any authenticated user can obtain from a front-end page, before generating a report containing every customer&amp;#39;s wallet transaction history, allowing any authenticated user, such as a subscriber, to disclose all users&amp;#39; names, email addresses, roles, transaction amounts, payment methods and dates.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/10/2026

CVE-2026-94245

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the user submitting a wallet transfer owns the wallet being debited, allowing any authenticated user, including one with only the Subscriber role, to move an arbitrary user&amp;#39;s wallet balance, including an administrator&amp;#39;s, into an account they control.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/10/2026

CVE-2026-94246

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the wallet account named in a withdrawal submission belongs to the user making it, allowing any authenticated user, such as a subscriber, to file a withdrawal request against another user&amp;#39;s wallet for an amount and a payout destination of their choosing, and to indefinitely prevent that user from submitting withdrawals of their own.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/10/2026

CVE-2026-86828

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** The BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallback archive library is used, allowing high-privileged users to write files outside the intended restore directory, potentially leading to remote code execution.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/10/2026

CVE-2026-5769

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability in Brocade SANnav before 3.0.1 can have the Brocade Fabric OS switch admin password captured in plaintext within a memory swap file on the server hosting the Brocade SANnav Virtual Machine (VM). This can happen when the SANnav server encounters an Out Of Memory (OOM) condition. The vulnerability could allow an authenticated admin user with access to the server hosting the SANnav to potentially view the memory swap file and access the password(s).
Gravedad CVSS v4.0: MEDIA
Última modificación:
08/10/2026

CVE-2026-86826

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** The BackWPup WordPress plugin before 5.7.7 does not properly restrict web access to the working directory it uses during backup restores, allowing unauthenticated attackers, on webservers that do not honour .htaccess rules such as NGINX, to download the full backup archive (database dump and site files, including credentials and secret keys) left behind by an interrupted restore.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/10/2026

CVE-2026-86827

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** The BackWPup WordPress plugin before 5.7.7 does not verify that a request to its cron-triggered backup execution handler actually originates from WordPress&amp;#39;s internal scheduled-event dispatch, allowing unauthenticated attackers to force any existing backup job to run immediately, independent of its configured trigger type or schedule.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/10/2026

CVE-2026-5048

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Brocade SANnav before 3.0.0a, an SQL Injection vulnerability in various external API inventories have a vulnerability that allows an authenticated attacker to inject malicious data into some of the REST API -query parameters.
Gravedad CVSS v4.0: MEDIA
Última modificación:
08/10/2026

CVE-2026-5049

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** A path traversal vulnerability affects the The Zone Alias Import flow feature in Brocade SANnav before 3.0.0a. A local authenticated attacker can write an uploaded content outside the intended directory.
Gravedad CVSS v4.0: MEDIA
Última modificación:
08/10/2026

CVE-2026-107459

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
08/10/2026