Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-21662

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files.<br /> <br /> This issue affects FM Systems Employee: before 2025.3.1.
Gravedad CVSS v4.0: MEDIA
Última modificación:
10/08/2026

CVE-2026-67822

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled &amp;#39;GO&amp;#39; and &amp;#39;index&amp;#39; parameters into a 64-byte stack buffer without length restriction, leading to stack overflow.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
31/07/2026

CVE-2026-58047

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HTTP Smuggling in cPanel allows potential leak of credentials.
Gravedad CVSS v4.0: MEDIA
Última modificación:
07/08/2026

CVE-2026-58048

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
07/08/2026

CVE-2026-54707

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files setting in cli/onionshare_cli/web/receive_mode.py, where ReceiveModeRequest._get_file_stream() writes multipart file[] data to disk despite the text-only setting. This issue is fixed in version 2.6.4.
Gravedad CVSS v3.1: MEDIA
Última modificación:
01/08/2026

CVE-2026-52856

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.
Gravedad CVSS v3.1: ALTA
Última modificación:
31/07/2026

CVE-2026-54706

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/send_base_mode.py through SendBaseModeWeb.set_file_info() and stream_individual_file(), allowing remote recipients of Share or Website mode to read local files outside the selected directory. This issue is fixed in version 2.6.4.
Gravedad CVSS v3.1: MEDIA
Última modificación:
31/07/2026

CVE-2026-52855

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token_id}}, and {{config.docker.registries}} from the full daemon configuration. This issue is fixed in version 1.12.3.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
31/07/2026

CVE-2026-67607

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thread_cleanup() function of ftpserv.c that allows remote unauthenticated attackers to destabilize or crash the daemon by triggering unsynchronized access to shared per-connection state without holding the required mutex lock. Attackers can send a data-transfer command such as LIST followed immediately by ABOR to exploit the missing synchronization on shared context and detached thread id reuse, resulting in daemon destabilization or crash which can lead to a denial of service. The 2.3.1 patch only narrowed the timing window (an extra re-check and reordered cleanup), it never added the missing lock, so the underlying race remains.
Gravedad CVSS v4.0: ALTA
Última modificación:
03/08/2026

CVE-2026-59231

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server to arbitrary attacker-chosen destinations via unvalidated URLs stored in the finding images field or the report client_logo field, which the server-side headless browser fetches while rendering the report.
Gravedad CVSS v4.0: MEDIA
Última modificación:
31/07/2026

CVE-2026-59232

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the create or update lead permission to execute arbitrary JavaScript in the application origin via HTML markup stored in the lead name field, which the view renders through Blade&amp;#39;s unescaped output directive and inside a JavaScript string literal in an onclick attribute.
Gravedad CVSS v4.0: MEDIA
Última modificación:
31/07/2026

CVE-2026-56569

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.
Gravedad CVSS v3.1: MEDIA
Última modificación:
05/08/2026