Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-49349

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvertently leaked to external servers. A prerequisite for this attack is a malicious registry server, a malicious blob store, or a registry that does not restrict the external URLs for foreign blobs. Version 0.11.5 fixes the issue.
Gravedad CVSS v3.1: MEDIA
Última modificación:
12/08/2026

CVE-2026-49262

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding. A Time-of-Check to Time-of-Use (TOCTOU) race condition exists between the URL validation phase and the actual HTTP request phase, allowing attackers to access internal network resources and cloud metadata endpoints. Version 0.10.4 fixes the issue.
Gravedad CVSS v3.1: BAJA
Última modificación:
12/08/2026

CVE-2026-47234

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::setCookie()` logs full cookie values and `Session::start()` logs the current session ID. In a real Admidio deployment this includes both the active session cookie and the persistent auto-login cookie. Anyone with access to the log sink can recover live bearer-style credentials from the logs. Version 5.0.10 contains a fix.
Gravedad CVSS v3.1: MEDIA
Última modificación:
12/08/2026

CVE-2026-47233

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `case 'item_delete':` in `modules/inventory.php`. The same fix was not applied to the sibling `case 'field_delete':` handler, which destroys an entire inventory field definition, cascading to every `adm_inventory_item_data` row that referenced that field and every `adm_inventory_field_options` entry. The handler validates only a session-bound CSRF token; there is no `isAdministratorInventory()` check at the controller level, and `Admidio\Inventory\Entity\ItemField::delete()` does not enforce one at the entity level either (unlike its sibling `ItemField::save()`, which does check `$gCurrentUser->isAdministrator()`). Any user who can log in to the site can permanently destroy a non-system inventory field by sending one POST. Version 5.0.10 provides an updated fix.
Gravedad CVSS v3.1: MEDIA
Última modificación:
13/08/2026

CVE-2026-18171

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge grant is added to the sandbox's policy-share allowlist with no access mode. The directory stays writable at its shared-export path, so unprivileged code inside the sandbox can derive that path and write to a host directory the operator attached read-only.
Gravedad CVSS v4.0: MEDIA
Última modificación:
18/08/2026

CVE-2026-14479

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malicious actor may leverage this vulnerability to cause the NT AUTHORITY\SYSTEM service to terminate unexpectedly, resulting in a denial-of-service condition.
Gravedad CVSS v3.1: MEDIA
Última modificación:
12/08/2026

CVE-2026-14478

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability.
Gravedad CVSS v3.1: ALTA
Última modificación:
13/08/2026

CVE-2025-59324

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
13/08/2026

CVE-2025-59322

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext.
Gravedad CVSS v3.1: ALTA
Última modificación:
13/08/2026

CVE-2025-59323

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for code execution in the context of high privilege.
Gravedad CVSS v3.1: ALTA
Última modificación:
13/08/2026

CVE-2025-59320

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM.
Gravedad CVSS v3.1: MEDIA
Última modificación:
12/08/2026

CVE-2025-59321

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
13/08/2026