Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-18197

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper neutralization of input during web page generation (&amp;#39;cross-site scripting&amp;#39;) vulnerability in Link Library allows Cross-Site Scripting (XSS).<br /> <br /> This issue affects Link Library: before 7.9.4.
Gravedad CVSS v4.0: MEDIA
Última modificación:
30/07/2026

CVE-2026-33267

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Input Validation vulnerability in Apache Traffic Server.<br /> <br /> This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3.<br /> <br /> Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
Gravedad CVSS v4.0: ALTA
Última modificación:
05/08/2026

CVE-2026-22068

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Regular Expression without Anchors vulnerability in Apache Traffic Server.<br /> <br /> This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14.<br /> <br /> Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
Gravedad CVSS v4.0: MEDIA
Última modificación:
05/08/2026

CVE-2026-24033

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Inconsistent Interpretation of HTTP Requests (&amp;#39;HTTP Request/Response Smuggling&amp;#39;) vulnerability in Apache Traffic Server.<br /> <br /> This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3, from 9.0.0 through 9.2.14.<br /> <br /> Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
Gravedad CVSS v4.0: MEDIA
Última modificación:
05/08/2026

CVE-2026-63236

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An improper access control vulnerability in<br /> Koollab LMS allowed an<br /> unauthenticated attacker to read another user&amp;#39;s name, internal identifier,<br /> scores, lesson status, lesson position, and cached lesson state via the SCORM<br /> API endpoint.
Gravedad CVSS v3.1: BAJA
Última modificación:
30/07/2026

CVE-2026-63237

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A TOTP two-factor authentication bypass vulnerability in<br /> Koollab LMS allowed an<br /> attacker to supply a client-controlled seed to generate a matching one-time<br /> password and bypass the second authentication factor, potentially enabling<br /> unauthorised access to administrator accounts.
Gravedad CVSS v3.1: MEDIA
Última modificación:
30/07/2026

CVE-2026-63238

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated<br /> attacker to take over any account, including administrator accounts, by<br /> supplying a valid user UUID without providing primary credentials via the 2FA<br /> validation endpoint.
Gravedad CVSS v3.1: MEDIA
Última modificación:
30/07/2026

CVE-2026-63239

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A hard-coded AWS IAM credentials vulnerability<br /> in Koollab LMS allowed<br /> an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing<br /> sensitive data and enabling malicious content injection, job manipulation, or<br /> email interception.
Gravedad CVSS v3.1: MEDIA
Última modificación:
30/07/2026

CVE-2026-63240

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An information disclosure vulnerability in Koollab LMS allowed an authenticated learner<br /> to obtain correct quiz answers from the course status endpoint without<br /> completing the assessment legitimately, compromising the integrity of<br /> assessments.
Gravedad CVSS v3.1: MEDIA
Última modificación:
30/07/2026

CVE-2026-63241

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An insecure direct object reference<br /> vulnerability in Koollab LMS allowed an authenticated user to query the course completion progress<br /> of any other user without authorisation, disclosing private learning progress<br /> information.
Gravedad CVSS v3.1: BAJA
Última modificación:
30/07/2026

CVE-2026-63242

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A business logic vulnerability in Koollab LMS<br /> allowed an<br /> authenticated learner to set their lesson completion status to completed via<br /> the SCORM commit endpoint without viewing the lesson material, compromising<br /> training and completion records.
Gravedad CVSS v3.1: MEDIA
Última modificación:
30/07/2026

CVE-2026-63228

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An unrestricted image upload vulnerability in<br /> Koollab LMS allowed<br /> an authenticated attacker to upload malicious content disguised as an image<br /> file via the feedback mail registration endpoint, potentially enabling further<br /> attacks on the server.
Gravedad CVSS v3.1: BAJA
Última modificación:
30/07/2026