Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-57284

Fecha de publicación:
24/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, allowing attackers to instantiate types related to job or system configuration other than Pipeline steps.
Gravedad CVSS v3.1: MEDIA
Última modificación:
26/06/2026

CVE-2026-57282

Fecha de publicación:
24/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper script, allowing attackers able to control the name of a build's working directory to execute arbitrary operating system commands on the agent.
Gravedad CVSS v3.1: MEDIA
Última modificación:
26/06/2026

CVE-2026-57287

Fecha de publicación:
24/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets when displaying historical job and agent configurations, allowing attackers with Extended Read permission to view encrypted secret values that would otherwise be redacted.
Gravedad CVSS v3.1: MEDIA
Última modificación:
26/06/2026

CVE-2026-57286

Fecha de publicación:
24/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Read permission to obtain information about the SCM repository used by a job, such as branch names, tag names, and revision metadata.
Gravedad CVSS v3.1: MEDIA
Última modificación:
26/06/2026

CVE-2026-57281

Fecha de publicación:
24/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy scripts to execute code outside the sandbox if a suitable script is present on the classpath of the component that evaluates the script.
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-57280

Fecha de publicación:
24/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts, allowing attackers able to provide such scripts to invoke arbitrary constructors and bypass the sandbox protection.
Gravedad CVSS v3.1: ALTA
Última modificación:
26/06/2026

CVE-2026-29034

Fecha de publicación:
24/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Gravedad: Pendiente de análisis
Última modificación:
24/06/2026

CVE-2026-35025

Fecha de publicación:
24/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory ACL restrictions by prefixing paths with /proc/self/root in the RNFR command handler. Attackers can exploit the unresolved symlink components in dir_canonical_path() to cause dir_check() to perform lexical path comparisons that match no configured Directory block, enabling rename operations on files in DenyAll-protected directories and subsequent retrieval of those files. Mitigation: Sessions configured with DefaultRoot (chroot) are not affected, as chroot changes the directory to which /proc/self/root resolves.
Gravedad CVSS v4.0: ALTA
Última modificación:
14/07/2026

CVE-2026-12537

Fecha de publicación:
24/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker to achieve pre-sandbox host-level code execution a maliciously crafted .gemini/.env file.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
02/07/2026

CVE-2026-56761

Fecha de publicación:
24/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** hono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to inject unintended html by using malformed attribute names. Attackers can craft specially crafted attribute keys containing characters like quotes or angle brackets to break html tag boundaries and inject arbitrary attributes or elements.
Gravedad CVSS v4.0: MEDIA
Última modificación:
26/06/2026

CVE-2026-56351

Fecha de publicación:
24/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that allows authenticated users to inject arbitrary SQL through unescaped identifier values in node configuration parameters. Attackers with workflow creation permissions can supply specially crafted table or column names to execute unauthorized database commands and compromise data integrity.
Gravedad CVSS v4.0: MEDIA
Última modificación:
26/06/2026

CVE-2026-56358

Fecha de publicación:
24/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger node's CSS sanitization that allows authenticated users to inject malicious scripts. Attackers with workflow creation permissions can inject XSS payloads that execute persistently for all form visitors, enabling form hijacking and phishing attacks.
Gravedad CVSS v4.0: MEDIA
Última modificación:
26/06/2026