Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-53414

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.
Gravedad CVSS v3.1: MEDIA
Última modificación:
11/08/2026

CVE-2026-53416

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access.
Gravedad CVSS v3.1: ALTA
Última modificación:
11/08/2026

CVE-2026-48766

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to exfiltrate stored OpenAI-compatible API keys by invoking the OpenAI model-listing helper with an attacker-controlled `baseUrl`. The vulnerable path decrypts the selected workspace credential, creates an OpenAI client with the secret in both `apiKey` and the explicit `api-key` header, and then sends the outbound request to the caller-supplied URL. Because the permission check accepts any readable workspace member and `listCredentials` reveals credential identifiers to guests, a guest can force the server to deliver the workspace secret to attacker infrastructure. Version 3.17.0 patches the issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
12/08/2026

CVE-2026-53413

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access.
Gravedad CVSS v3.1: ALTA
Última modificación:
12/08/2026

CVE-2026-53415

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access.
Gravedad CVSS v3.1: ALTA
Última modificación:
13/08/2026

CVE-2026-48495

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JSON `state` parameter and trusts the embedded `workspaceId`, `typebotId`, `blockId`, and `redirectUrl` without cryptographic integrity protection or authorization checks. The callback route is authenticated, but it does not verify that the authenticated user has write access to the target workspace or Typebot before creating credentials in the workspace or updating Typebot groups. An authenticated user who can obtain a valid Google OAuth `code` can alter the `state` value to create Google Sheets credentials in another workspace and, if target IDs are known, attach those credentials to a block in another Typebot. Version 3.17.0 patches the issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
13/08/2026

CVE-2026-42142

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getSheets`) does not validate workspace membership, allowing any authenticated user to access and decrypt another workspace's Google Sheets OAuth credentials and retrieve spreadsheet data (sheet names, IDs, column headers). Version 3.17.0 fixes the issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
11/08/2026

CVE-2026-19078

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or denied by an authenticated user, redirects them to an attacker-controlled website. This could enable phishing attacks, potentially tricking users into revealing sensitive information.
Gravedad CVSS v3.1: MEDIA
Última modificación:
14/08/2026

CVE-2026-19546

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z.<br /> <br /> For a detailed Statement, Description and Mitigation please reffer to the original https://access.redhat.com/security/cve/cve-2026-19546.
Gravedad CVSS v3.1: ALTA
Última modificación:
14/08/2026

CVE-2026-18638

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single request, by calling SetPassword with a username that does not exist.
Gravedad CVSS v3.1: MEDIA
Última modificación:
11/08/2026

CVE-2026-18639

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim and do not actually verify the email.<br /> <br /> This allows a user to impersonate another user by setting their email address within the IdP, allowing account takeover.
Gravedad CVSS v3.1: ALTA
Última modificación:
11/08/2026

CVE-2026-18640

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook record outside the org&amp;#39;s data store directory. The file written must have an extension of ".json.db" but can otherwise overwrite other metadata files (such as ACL records, hunts etc). This can corrupt these files and cause data corruption.
Gravedad CVSS v3.1: ALTA
Última modificación:
11/08/2026