Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-27345

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce
Gravedad CVSS v3.1: ALTA
Última modificación:
14/08/2026

CVE-2026-27380

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Editor PHP Object Injection in Car Rental Manager
Gravedad CVSS v3.1: ALTA
Última modificación:
14/08/2026

CVE-2026-19716

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authenticated attacker to execute arbitrary JavaScript in the browser of another authenticated user via a crafted username, because the frontend escapes the username with escapeHTML() before interpolating it into the onclick attribute of the account deletion button, but the browser HTML-decodes attribute values before the JavaScript engine parses the handler, allowing an encoded single quote (') to break out of the string literal and inject arbitrary JavaScript that executes when the victim clicks the delete button for that account.
Gravedad CVSS v4.0: MEDIA
Última modificación:
13/08/2026

CVE-2026-21832

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions.
Gravedad CVSS v3.1: MEDIA
Última modificación:
28/08/2026

CVE-2025-62314

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under certain conditions.
Gravedad CVSS v3.1: MEDIA
Última modificación:
28/08/2026

CVE-2025-62315

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in unintended behavior or security impact under certain conditions.
Gravedad CVSS v3.1: BAJA
Última modificación:
28/08/2026

CVE-2025-62318

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain conditions.
Gravedad CVSS v3.1: BAJA
Última modificación:
28/08/2026

CVE-2026-73583

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially crafted message, the attacker can cause out-of-bounds memory access, leading to the termination of the provider-manager process and a denial of service. This could also potentially result in limited unintended information disclosure.
Gravedad CVSS v3.1: MEDIA
Última modificación:
25/08/2026

CVE-2026-73584

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to an arbitrary file. This can lead to privileged file corruption or a denial of service (DoS) on the system.
Gravedad CVSS v3.1: MEDIA
Última modificación:
25/08/2026

CVE-2026-73585

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an attacker can redirect privileged writes to an arbitrary file during script execution in a privileged context. This can lead to the overwrite of root-owned files, potentially disrupting system services or operation. Exploitation is conditional on the script running with elevated privileges and may be mitigated by sticky-directory symlink protections.
Gravedad CVSS v3.1: MEDIA
Última modificación:
25/08/2026

CVE-2026-6470

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Gravedad CVSS v3.1: MEDIA
Última modificación:
29/08/2026

CVE-2026-6464

Fecha de publicación:
13/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Gravedad CVSS v3.1: ALTA
Última modificación:
29/08/2026