Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-18649

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.
Gravedad CVSS v3.1: ALTA
Última modificación:
11/08/2026

CVE-2026-0637

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values.<br /> <br /> A malicious actor with access to the &amp;#39;wso2carbon&amp;#39; log files could retrieve sensitive information, such as user credentials or other confidential data, that was inadvertently logged due to misconfiguration, potentially leading to unauthorized access.
Gravedad CVSS v3.1: MEDIA
Última modificación:
12/08/2026

CVE-2025-15039

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps.<br /> <br /> Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
12/08/2026

CVE-2025-14779

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to enforce organizational boundaries, leading to the removal of secrets associated with that type across all organizations.<br /> <br /> Exploitation of this vulnerability can result in the unintended deletion of secrets across the entire deployment, potentially causing configuration failures, service interruptions, and a denial-of-service condition. This vulnerability requires delete permissions for the Secret Type Management REST API, which are by default only granted to administrators.
Gravedad CVSS v3.1: BAJA
Última modificación:
10/08/2026

CVE-2025-13909

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead to the exposure of personally identifiable information.<br /> <br /> Successful exploitation allows an attacker to disclose personally identifiable information of users in different tenants, resulting in privacy violations and potential regulatory non-compliance. This may include unauthorized access to user details such as mobile numbers.
Gravedad CVSS v3.1: MEDIA
Última modificación:
10/08/2026

CVE-2025-12627

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This allows an attacker who has obtained an access token for an impersonated user to leverage the refresh token grant to obtain new access tokens, extending their ability to act as the legitimate user.<br /> <br /> An attacker who gains access to an impersonated user&amp;#39;s access token can exploit this weakness to renew their authorization. This results in the continued ability to perform actions on behalf of the actual user, compromising log integrity and traceability by masking the true actor.
Gravedad CVSS v3.1: BAJA
Última modificación:
10/08/2026

CVE-2025-13736

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays their canonical username, while for non-existent users, it echoes the original input. This occurs regardless of the validate_username configuration.<br /> <br /> The discovery of valid usernames can increase the risk of brute force attacks, social engineering attacks, and targeted information leakage. Attackers can leverage this information to craft more effective phishing campaigns or social engineering tactics to compromise user accounts or extract sensitive data.
Gravedad CVSS v3.1: BAJA
Última modificación:
12/08/2026

CVE-2025-13394

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HTTP GET method for these operations, and while the SameSite=Lax cookie attribute is employed for mitigation, this mechanism is bypassed as it permits cookies to be sent with cross-origin top-level navigation requests, including GET requests. This allows an attacker to trick an authenticated user&amp;#39;s browser into unknowingly executing unintended actions.<br /> <br /> An attacker can exploit this vulnerability to perform unauthorized state-altering requests on behalf of authenticated users. This could lead to consequences such as data modification, account changes, or other actions that could result in data compromise or loss of user control over their account. However, this attack is only feasible if the Carbon console and related services are exposed to the public internet, which is not recommended according to WSO2&amp;#39;s security guidelines.
Gravedad CVSS v3.1: MEDIA
Última modificación:
12/08/2026

CVE-2024-6832

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attempt authentication with invalid credentials without triggering the lockout mechanism for users within active stores.<br /> <br /> When the account locking mechanism is bypassed due to the inaccessibility of secondary user stores, users in accessible user stores are left vulnerable to brute force attacks. A malicious actor can exploit this by attempting numerous invalid password combinations against a user account without the expected account lockout consequence.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/08/2026

CVE-2025-11850

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary user store and bypasses the primary user store during search and uniqueness checks. This allows a subject to be associated with an unintended local account if the same lookup claim (e.g., username or email) exists in both the primary and a secondary store.<br /> <br /> If duplicate claim values exist across user stores, this issue can lead to identity confusion due to incorrect implicit associations when using an external Identity Provider (IDP). Legitimate user accounts in the primary user store may fail to associate correctly with their corresponding external IDP accounts, potentially restricting access if the secondary account has fewer privileges. Deployments are not affected if no secondary user stores are configured, implicit association is disabled, or claim values are globally unique.
Gravedad CVSS v3.1: MEDIA
Última modificación:
10/08/2026

CVE-2024-8995

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused.<br /> <br /> If an attacker possesses both the authorization code and the associated client credentials (client ID and client secret), they can leverage these unused codes to obtain access tokens on behalf of users who have already been deleted. This may lead to unauthorized access to sensitive resources and services, contingent on the scopes originally authorized for the compromised authorization code.
Gravedad CVSS v3.1: MEDIA
Última modificación:
13/08/2026

CVE-2023-7353

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Gravedad: Pendiente de análisis
Última modificación:
06/08/2026