Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-17008

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status in its PayPal IPN handler and marks an order paid on an order-token match alone, so a buyer who pays an arbitrary small amount can have a full-price order marked paid.
Gravedad CVSS v3.1: MEDIA
Última modificación:
12/08/2026

CVE-2026-15045

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against the customer's actual stored balance during checkout, allowing authenticated customers to arbitrarily reduce their own order total, including down to zero, and complete checkout without paying the merchant.
Gravedad CVSS v3.1: MEDIA
Última modificación:
12/08/2026

CVE-2026-15213

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-transfer settlement callback: an unauthenticated request can flip an order from unpaid to settled purely from an order number and a status flag, with no signature, amount, or origin check. Because these are pay-later methods, an attacker can mark their own unpaid order as settled and obtain fulfilment without paying.
Gravedad CVSS v3.1: MEDIA
Última modificación:
12/08/2026

CVE-2026-16621

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an order in its PayPal return handler: it reads attacker-controlled parameters, performs no amount comparison and no order-ownership check, and completes the order even when the server-side gateway verification fails, allowing an unauthenticated attacker to mark arbitrary orders as paid without paying.
Gravedad CVSS v3.1: MEDIA
Última modificación:
12/08/2026

CVE-2026-11325

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Description<br /> <br /> <br /> <br /> Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in `src/index.ts` reachable from certain GitHub Actions workflow configurations. Successful exploitation may expose workflow secrets such as CLOUDFLARE_API_TOKEN and GITHUB_TOKEN to an attacker. Because this repository has been deprecated since 2024, Cloudflare will not be issuing patches. To remediate this issue, we recommend migrating to `cloudflare/wrangler-action` immediately. Consumers who have already migrated are not affected.<br /> <br /> <br /> <br /> <br /> Sunset Date<br /> <br /> <br /> <br /> The cloudflare/pages-action repository will be removed on 2026-09-18. Consumers must complete migration before 18th September to avoid CI disruption.<br /> <br /> <br /> <br /> <br /> Affected Versions<br /> <br /> <br /> <br /> All published versions of cloudflare/pages-action, including consumers pinned to the v1 moving tag.<br /> <br /> <br /> <br /> <br /> Patched Versions<br /> <br /> <br /> <br /> None. This repository will not receive further updates, including security patches.<br /> <br /> <br /> <br /> <br /> Resolution / Migration Path<br /> Migrate all workflows using cloudflare/pages-action to `cloudflare/wrangler-action` before 2026-09-18. Refer to the wrangler-action README for the equivalent step configuration and migration guidance.<br /> <br /> <br /> <br /> <br /> Credit<br /> <br /> <br /> <br /> Thanks to @agentka99 and @beg1nn3r for reporting their findings via Cloudflare&amp;#39;s HackerOne program that informe
Gravedad CVSS v3.1: ALTA
Última modificación:
12/08/2026

CVE-2026-68868

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Google Cloud Secret Manager secrets backend in Apache Airflow&amp;#39;s Google provider never applied the team scope when resolving Connections and Variables: the caller&amp;#39;s `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnostic secret name. In a deployment running multi-team mode with this backend, a task or Dag belonging to one team resolved another team&amp;#39;s Connection or Variable, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backend. Users are advised to upgrade to apache-airflow-providers-google 22.3.0 or later, which builds and applies the team-scoped secret name.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/08/2026

CVE-2026-64951

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic occurs which may crash the server process.<br /> <br /> The problem is a Divide by Zero bug in the ShouldPadFile() function.
Gravedad CVSS v3.1: BAJA
Última modificación:
12/08/2026

CVE-2026-64952

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The hunt_delete() VQL function allows deleting hunts. <br /> <br /> Velociraptor misapplied the permission check requiring only COLLECT_CLIENT (usually assigned to the "investigator" role) instead of the "DELETE_RESULTS" permission (usually only assigned to "administrators").
Gravedad CVSS v3.1: MEDIA
Última modificación:
12/08/2026

CVE-2026-64955

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution. <br /> <br /> Velociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data exports.<br /> <br /> It is not clear if the vulnerability is actually in Microsoft Excel treating a CSV data file as executable content, or if Velociraptor should be sanitizing the data to prevent Excel from executing it. However, since this is such a common use case for Velociraptor we decided to highlight it in an advisory.
Gravedad CVSS v3.1: MEDIA
Última modificación:
12/08/2026

CVE-2026-67284

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud
Gravedad CVSS v4.0: MEDIA
Última modificación:
12/08/2026

CVE-2026-18663

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without clearing the SLAPI_REQCONTROLS pblock slot. Operation teardown then frees the same pointer again, causing a double-free. An unauthenticated remote attacker can trigger this with a single BIND request carrying a critical Session Tracking control, resulting in heap corruption and potential denial of service.
Gravedad CVSS v3.1: MEDIA
Última modificación:
14/08/2026

CVE-2026-18652

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Velociraptor allows reading Stacked result sets from the GUI.  Velociraptor&amp;#39;s multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI is not correctly checked against the prefix deny list, allowing result sets to read from denied prefixes.<br /> <br /> In particular, a user with read access to the root org can access result sets from child orgs.
Gravedad CVSS v3.1: MEDIA
Última modificación:
24/08/2026