Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-13186

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-controlled input, enabling attacker-controlled deserialization and remote code execution.
Gravedad CVSS v3.1: ALTA
Última modificación:
24/07/2026

CVE-2026-13187

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processing and enabling chained exploitation.
Gravedad CVSS v3.1: ALTA
Última modificación:
24/07/2026

CVE-2026-13190

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution.
Gravedad CVSS v3.1: ALTA
Última modificación:
24/07/2026

CVE-2026-13182

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-13183

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-13184

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-13181

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affected deployments.
Gravedad CVSS v3.1: ALTA
Última modificación:
24/07/2026

CVE-2026-8152

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack.<br /> <br /> <br /> When Unblu Spark is deployed with com.unblu.identifier.siteEmbeddedSetup=true, it runs in the same origin as the host application. Any JavaScript injected through this vulnerability therefore executes with full access to the host application&amp;#39;s cookies, DOM, and same-origin APIs — an attacker can reach all resources of the host application, not just Unblu&amp;#39;s. This expanded blast radius is the reason on-premises deployments using this configuration are rated CRITICAL.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
22/07/2026

CVE-2026-44191

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts settings, allowing an attacker to inject shell separators. This can be triggered automatically during Language Server initialization or manually when executing a playbook. Successful exploitation leads to remote code execution (RCE) on the victim&amp;#39;s machine with the privileges of the Visual Studio Code user, potentially resulting in a complete system compromise.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-16270

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule can add an unsafe regex to a field. When someone provide the proper string it can result in a DoS attack.<br /> <br /> <br /> This issue was fixed in version 0.6.4.
Gravedad CVSS v4.0: MEDIA
Última modificación:
22/07/2026

CVE-2026-65599

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Google Service Account key, the full PEM private key was mistakenly placed in the JWT header&amp;#39;s kid field (intended only for a key identifier). Because JWT headers are Base64-encoded rather than encrypted, the private key could be recovered by anything that logged or inspected the JWT. An attacker who obtained the key could impersonate the service account and access or modify any Google Cloud resource it was authorized to use. Only instances using Google Service Account credentials are affected.
Gravedad CVSS v4.0: MEDIA
Última modificación:
22/07/2026

CVE-2026-65603

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Grav Login plugin (grav-plugin-login) versions
Gravedad CVSS v4.0: ALTA
Última modificación:
22/07/2026