Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-77539

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
28/08/2026

CVE-2026-77540

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
28/08/2026

CVE-2026-59683

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of CVE-2026-59682). This allows either a full system compromise from local or remote (if the daemon is running as root) or a full account takeover (if the daemon is running in user context).
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
26/08/2026

CVE-2026-2388

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Reviews and Rating – Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.10. This is due to the wp_display() shortcode handler, used by multiple shortcodes, allowing attacker-controlled html_tags values to define raw HTML tags and then embedding untrusted vicinity content inside those tags. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/08/2026

CVE-2026-18794

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The OpenRGB network protocol allows attackers to cause memory exhaustion and out-of-bounds memory reads and writes by passing inconsistent data.
Gravedad CVSS v4.0: ALTA
Última modificación:
26/08/2026

CVE-2026-19042

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A command injection vulnerability in TeamViewer Full<br /> Client and Host for Linux prior to version 15.81.5 allows a remote attacker to<br /> execute arbitrary commands in the context of the current user via a specially<br /> crafted URL sent through the out-of-session chat feature. Exploitation requires<br /> user interaction by clicking the malicious link.
Gravedad CVSS v3.1: ALTA
Última modificación:
26/08/2026

CVE-2026-59682

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0rc3.
Gravedad CVSS v4.0: ALTA
Última modificación:
26/08/2026

CVE-2026-16444

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper<br /> neutralization of path traversal sequences in TeamViewer Desktop Clients prior<br /> Version 15.81.5 allows an authenticated remote session participant to write files<br /> to unintended locations on the local file system via file transfer or virtual<br /> file clipboard mechanisms. An attacker can leverage this behavior to achieve<br /> arbitrary file write and potentially execute code with the privileges of the<br /> affected user.
Gravedad CVSS v3.1: ALTA
Última modificación:
27/08/2026

CVE-2026-80235

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
26/08/2026

CVE-2026-80236

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Efence developed by Thinking Software Technology has a SQL Injection vulnerability. Unauthenticated remote attackers can access file upload functionality and read database contents.
Gravedad CVSS v4.0: ALTA
Última modificación:
26/08/2026

CVE-2026-80237

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Authenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Gravedad CVSS v4.0: ALTA
Última modificación:
26/08/2026

CVE-2026-77533

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
28/08/2026