Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-9680

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces by default.
Gravedad CVSS v3.1: MEDIA
Última modificación:
28/07/2026

CVE-2026-15267

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL Injection via the 'wppm_proj_filter' parameter in versions up to, and including, 5.0.9. This is due to insufficient escaping on the user-supplied parameter and the lack of sufficient preparation on the existing SQL query — the value is re-read at line 144 using only sanitize_text_field() (overwriting the earlier absint() result), then concatenated into the SQL WHERE clause as an unquoted numeric operand using only esc_sql(), which does not protect against injection in that context, and finally string-interpolated into the $wpdb->prepare() format string, bypassing parameterization entirely. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Gravedad CVSS v3.1: MEDIA
Última modificación:
28/07/2026

CVE-2026-8167

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper neutralization of input during web page generation (&amp;#39;cross-site scripting&amp;#39;) vulnerability in THEWP Digital Solutions News Theme V8 allows Reflected XSS.<br /> <br /> This issue affects News Theme V8: through 16.06.2026.
Gravedad CVSS v3.1: MEDIA
Última modificación:
28/07/2026

CVE-2026-44387

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user&amp;#39;s web browser.
Gravedad CVSS v4.0: MEDIA
Última modificación:
28/07/2026

CVE-2026-59764

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/07/2026

CVE-2026-61376

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/07/2026

CVE-2026-14170

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Gravedad: Pendiente de análisis
Última modificación:
28/07/2026

CVE-2026-13161

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the &amp;#39;alldata[truebooker_user]&amp;#39; parameter in all versions up to, and including, 1.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The check_ajax_referer() nonce guard does not constitute an authentication or authorization barrier because the nonce is exposed to unauthenticated visitors on TrueBooker front-end booking pages; exploitation additionally requires that the required booking fields (category, service, person, date, and time slot) be present in the alldata POST parameter so that execution reaches the vulnerable SQL query branch.
Gravedad CVSS v3.1: ALTA
Última modificación:
28/07/2026

CVE-2026-14516

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the &amp;#39;staff_ids&amp;#39; parameter in all versions up to, and including, 27.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires a two-request chain: an attacker first calls the unauthenticated bookly_get_form_id action to seed a booking session carrying malicious staff_ids values, then triggers bookly_render_time to cause the tainted array to reach the vulnerable query; CSRF/nonce validation is absent on both endpoints, meaning this chain can be initiated cross-site.
Gravedad CVSS v3.1: ALTA
Última modificación:
28/07/2026

CVE-2026-14167

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due to incorrect authorization.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/07/2026

CVE-2026-14168

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.
Gravedad CVSS v3.1: ALTA
Última modificación:
30/07/2026

CVE-2026-14169

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could result in complete administrative unavailability of the device.
Gravedad CVSS v3.1: ALTA
Última modificación:
30/07/2026