Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-42494

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** [This CNA information record relates to multiple CVEs; the<br /> text explains which aspects/vulnerabilities correspond to which CVE.]<br /> <br /> The directory and Rock Ridge / SUSP walk in libfsimage&amp;#39;s iso9660 driver<br /> derives several lengths directly from attacker-controlled on-disk fields<br /> without validating them:<br /> <br /> * The directory loop itself assumes a good record length. This is<br /> CVE-2026-42494.<br /> <br /> * The calculation of the System Use area may underflow. This is<br /> CVE-2026-42495.<br /> <br /> * The Rock Ridge extension loop assumes a good (inner) record length.<br /> This is CVE-2026-62423.<br /> <br /> * The Rock Ridge NM record processing assumes a good entry length.<br /> This is CVE-2026-62424.<br /> <br /> * The Rock Ridge CE record processing assumes a good size and offset.<br /> This is CVE-2026-62425.
Gravedad CVSS v3.1: MEDIA
Última modificación:
28/07/2026

CVE-2026-42495

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** [This CNA information record relates to multiple CVEs; the<br /> text explains which aspects/vulnerabilities correspond to which CVE.]<br /> <br /> The directory and Rock Ridge / SUSP walk in libfsimage&amp;#39;s iso9660 driver<br /> derives several lengths directly from attacker-controlled on-disk fields<br /> without validating them:<br /> <br /> * The directory loop itself assumes a good record length. This is<br /> CVE-2026-42494.<br /> <br /> * The calculation of the System Use area may underflow. This is<br /> CVE-2026-42495.<br /> <br /> * The Rock Ridge extension loop assumes a good (inner) record length.<br /> This is CVE-2026-62423.<br /> <br /> * The Rock Ridge NM record processing assumes a good entry length.<br /> This is CVE-2026-62424.<br /> <br /> * The Rock Ridge CE record processing assumes a good size and offset.<br /> This is CVE-2026-62425.
Gravedad CVSS v3.1: MEDIA
Última modificación:
28/07/2026

CVE-2026-41874

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with access to the server file system to retrieve authentication details, potentially leading to privilege escalation.<br /> <br /> <br /> The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.<br /> <br /> <br /> <br /> Only version 6.7 was tested but all versions should be considered as vulnerable.
Gravedad CVSS v4.0: MEDIA
Última modificación:
30/07/2026

CVE-2026-18047

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in Dogtag PKI&amp;#39;s ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker can bypass the Tomcat authentication constraint while RESTEasy still routes the request to the handler, allowing unauthorized toggling of the ACME service state including persistent denial of service.
Gravedad CVSS v3.1: MEDIA
Última modificación:
28/07/2026

CVE-2026-18038

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function ExecTool.Execute of the file goclaw/internal/http/tools_invoke.go of the component jq Handler. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. The exploit has been published and may be used. This patch is called 1230. It is advisable to implement a patch to correct this issue.
Gravedad CVSS v4.0: BAJA
Última modificación:
28/07/2026

CVE-2026-15016

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Paid Memberships Pro – Content Restriction, User Registration, &amp; Paid Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Readonly User Field via [pmpro_member_profile_edit] Shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Gravedad CVSS v3.1: MEDIA
Última modificación:
28/07/2026

CVE-2026-15393

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Cozy Blocks – Page Builder for Gutenberg Editor &amp; FSE with 600+ Patterns, 58 Blocks &amp; Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via &amp;#39;postMeta.font.size&amp;#39; Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Gravedad CVSS v3.1: MEDIA
Última modificación:
28/07/2026

CVE-2026-16774

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs_send_email() AJAX handler. This is due to the wpcs_send_email() function being registered on both wp_ajax_wpcs_send_email and wp_ajax_nopriv_wpcs_send_email with no nonce verification, capability check, or rate limiting, while forwarding attacker-controlled recipient, subject, and body directly to wp_mail(). This makes it possible for unauthenticated attackers to send arbitrary emails to any recipient from the site&amp;#39;s domain, enabling spam, phishing, and abuse that can lead to the site&amp;#39;s IP/domain being blacklisted.
Gravedad CVSS v3.1: MEDIA
Última modificación:
28/07/2026

CVE-2026-4648

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios Tecnológicos S.L.U. (version used at Resurrection Fest 2025), which employs cards based on MIFARE Classic technology (FM11RF08S). The cryptographic weakness of the authentication algorithm allows an attacker to retrieve access keys using techniques known as Backdoored Nested Attack, read the wristband’s entire contents, and clone its credentials onto a compatible rewritable card. Exploitation of this vulnerability could enable the impersonation of other attendees, the fraudulent use of the balance associated with their wristbands, and financial losses for both the affected users and the event organizers.
Gravedad CVSS v4.0: MEDIA
Última modificación:
28/07/2026

CVE-2026-21047

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/07/2026

CVE-2026-16773

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. This makes it possible for unauthenticated attackers to exfiltrate full chat transcripts and associated user PII — including names, email addresses, and phone numbers — stored in the wpbot_user and wpbot_conversation tables to an attacker-controlled email address.
Gravedad CVSS v3.1: MEDIA
Última modificación:
28/07/2026

CVE-2026-13440

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the &amp;#39;message_popup&amp;#39; parameter in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit is possible because the &amp;#39;ajd_protected&amp;#39; nonce required by the create_popup handler is exposed to all unauthenticated frontend visitors via wp_localize_script under bogo_save_url.ajd_nonce, effectively bypassing the nonce-only access control.
Gravedad CVSS v3.1: ALTA
Última modificación:
28/07/2026