Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-14180

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the remaining chunk size and state flags. By sending a specially crafted request with an extremely large chunk size, an attacker can cause these values to overlap, tricking the parser into thinking a request has finished prematurely. This can allow a second, "smuggled" request to be processed out of sync, potentially bypassing security controls.
Gravedad CVSS v3.1: MEDIA
Última modificación:
14/08/2026

CVE-2026-11738

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
Gravedad CVSS v4.0: MEDIA
Última modificación:
12/08/2026

CVE-2026-11739

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A command injection vulnerability in certain affected NETGEAR Nighthawk <br /> devices allows a network-adjacent attacker with the ability to intercept<br /> and modify local network traffic (attacker in the middle) to compromise<br /> the confidentiality and integrity of the affected device.
Gravedad CVSS v4.0: MEDIA
Última modificación:
12/08/2026

CVE-2026-11814

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
Gravedad CVSS v4.0: MEDIA
Última modificación:
12/08/2026

CVE-2026-11734

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.
Gravedad CVSS v4.0: BAJA
Última modificación:
12/08/2026

CVE-2026-11735

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router&amp;#39;s software and functionality.
Gravedad CVSS v4.0: BAJA
Última modificación:
12/08/2026

CVE-2026-11736

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.
Gravedad CVSS v4.0: BAJA
Última modificación:
12/08/2026

CVE-2026-11737

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Insufficient input validation vulnerability in the listed <br /> NETGEAR models allows authenticated administrators connected to the <br /> local network to make unauthorized modification to the device software and <br /> functionality.
Gravedad CVSS v4.0: MEDIA
Última modificación:
12/08/2026

CVE-2026-11733

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device.
Gravedad CVSS v4.0: BAJA
Última modificación:
12/08/2026

CVE-2025-31114

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use of eval when processing metadata JSON. An attacker with access to the Fooocus web UI may be able to execute arbitrary code on the instance. As of time of publication, no known patched versions are available, but a suggested fix pull request is available.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
13/08/2026

CVE-2026-72920

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser, CreateAccessKey, PutPolicy, and related IAM RPCs to mint credentials and gain S3 administrative control. This issue is fixed in versions 4.24.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
11/08/2026

CVE-2026-73066

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract&amp;#39;s deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolve.cpp to wrap the convolution output-channel count, undersizing the forward-pass output buffer while writes use the unwrapped element count and causing a heap out-of-bounds write during OCR recognition. This issue is fixed in version 5.5.3.
Gravedad CVSS v4.0: MEDIA
Última modificación:
11/08/2026