Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-18663

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without clearing the SLAPI_REQCONTROLS pblock slot. Operation teardown then frees the same pointer again, causing a double-free. An unauthenticated remote attacker can trigger this with a single BIND request carrying a critical Session Tracking control, resulting in heap corruption and potential denial of service.
Gravedad CVSS v3.1: MEDIA
Última modificación:
14/08/2026

CVE-2026-18652

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Velociraptor allows reading Stacked result sets from the GUI.  Velociraptor&amp;#39;s multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI is not correctly checked against the prefix deny list, allowing result sets to read from denied prefixes.<br /> <br /> In particular, a user with read access to the root org can access result sets from child orgs.
Gravedad CVSS v3.1: MEDIA
Última modificación:
24/08/2026

CVE-2026-67282

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
12/08/2026

CVE-2026-67283

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud
Gravedad CVSS v4.0: MEDIA
Última modificación:
12/08/2026

CVE-2026-19566

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths.<br /> <br /> The _encode method accepts any prefix length matching `(0|[1-9][0-9]*)` and passes it to _width2bits(), which builds the mask as `&amp;#39;1&amp;#39; x ($width + 8)`, one character per bit. The _inc() method then unpacks the packed mask into a Perl array of one scalar per byte, so the prefix length alone sets the allocation size: `::/100000000` builds a 100 MB string and a 12.5 million element array. The value being tested is parsed, not just the configured ranges: contains() builds a set from its argument, and _guess_coder() tries the IPv4 coder and then the IPv6 coder, so an IPv4-only set expands an oversized IPv6 prefix length before the mixed address width check rejects it.<br /> <br /> Any caller that passes untrusted input to contains() or add() can exhaust process memory. A prefix length above 128 is also stored as a range that does not match the requested block: 2001:db8::/129 stringifies back unchanged, contains() of its own base address returns false, and removing it from a set drops the base address while the set still prints as covering it.
Gravedad CVSS v3.1: ALTA
Última modificación:
12/08/2026

CVE-2026-19426

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the system.
Gravedad CVSS v4.0: ALTA
Última modificación:
12/08/2026

CVE-2025-41771

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.
Gravedad CVSS v4.0: MEDIA
Última modificación:
12/08/2026

CVE-2025-41770

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An unauthenticated denial-of-service vulnerability in the device&amp;#39;s PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted.
Gravedad CVSS v4.0: ALTA
Última modificación:
12/08/2026

CVE-2025-41769

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The device&amp;#39;s PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
13/08/2026

CVE-2026-66659

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Neutralization of Special Elements used in an SQL Command (&amp;#39;SQL Injection&amp;#39;) vulnerability in Essekia Tablesome Table allows Blind SQL Injection.<br /> <br /> This issue affects Tablesome Table: from n/a through 1.2.9.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
12/08/2026

CVE-2026-19594

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, and HTTP parameter pollution (CWE-141) via unencoded `&amp;`/`#`/`=` characters in query string values. An attacker with access to a downstream application built on snowflake.core could exploit the path traversal by supplying `..` as an object name, causing `snowflake.core` to issue REST requests against a parent resource or exploit the parameter pollution by injecting `&amp;`/`#`/`=` into a free-form name field to override constraints on swap, clone, or rename operations — all executed under the application&amp;#39;s privileged session. Successful exploitation requires the attacker to control an identifier or object-name string in an application built on snowflake.core that passes it to `snowflake.core` under a higher-privileged Snowflake session (e.g., an EXECUTE AS OWNER stored procedure, Streamlit app, or Native App). The fix is available in Snowflake Python API version 1.13.0, which also addresses several additional security findings. Users must manually upgrade.
Gravedad CVSS v3.1: ALTA
Última modificación:
12/08/2026

CVE-2026-19217

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTML tag before outputting it, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
Gravedad CVSS v3.1: MEDIA
Última modificación:
12/08/2026