Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-49997

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** SurrealDB is a scalable, distributed, collaborative, document-graph database for the realtime web. Prior to 3.1.0, Document::purge_edges in surrealdb/core/src/doc/delete.rs automatically removed graph edge records with permissions disabled through opt.clone().with_perms(false) when a connected node was deleted, bypassing the edge table's PERMISSIONS FOR delete and PERMISSIONS FOR select clauses. This issue is fixed in version 3.1.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
20/07/2026

CVE-2026-45804

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretrained flow can bypass the trust_remote_code guard because download() validates model_index.json and custom pipeline code before later loading from a cached folder that can change, allowing a Hub repository with custom .py pipeline code to execute through the custom pipeline flow without passing custom_pipeline or trust_remote_code=True. This issue is fixed in version 0.38.0.
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-47703

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.75, AdGuard Home's client-triggered DoQ forwarding path to a udp:// upstream reduced backend UDP DNS state by producing dns_id=0 or txid=0 and exposed a quoted-port ICMP source-port oracle, weakening DNS response matching for forwarded queries. This issue is fixed in version 0.107.75.
Gravedad CVSS v4.0: MEDIA
Última modificación:
15/07/2026

CVE-2026-45793

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConfiguration() validates GitHub OAuth tokens with the regex ^[.A-Za-z0-9_]+$ and interpolates rejected tokens into an UnexpectedValueException; GitHub Actions GITHUB_TOKEN values using the ghs__ format can contain -, fail validation, and be disclosed to stderr or CI logs. This issue is fixed in versions 1.10.28, 2.2.28, and 2.9.8.
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-48799

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authenticity against the payment provider shared secret and reads the target subscription identifier from the untrusted request body, allowing a low-privileged account to grant arbitrary organizations lifetime PRO subscriptions without payment. This issue is fixed in version 2.21.8.
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-20150

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** As part of Cisco&amp;#39;s ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.<br /> <br /> The vulnerabilities tracked by CVE-2026-20150 are related to improper access control&amp;nbsp;that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-20153

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** As part of Cisco&amp;#39;s ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.<br /> <br /> The vulnerabilities tracked by CVE-2026-20153 are related to improper input validation that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20.
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-20156

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** As part of Cisco&amp;#39;s ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.<br /> <br /> The vulnerabilities tracked by CVE-2026-20156 are related to improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119.
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-20157

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** As part of Cisco&amp;#39;s ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.<br /> <br /> The vulnerabilities tracked by CVE-2026-20157 are related to missing encryption that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-311.
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-20158

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** As part of Cisco&amp;#39;s ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.<br /> <br /> The vulnerabilities tracked by CVE-2026-20158 are related to improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-20187

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** As part of Cisco&amp;#39;s ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.<br /> <br /> The vulnerabilities tracked by CVE-2026-20187 are related to improper handling of exceptional conditions that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-703.
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-20146

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials.&amp;nbsp;<br /> <br /> This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system.
Gravedad CVSS v3.1: MEDIA
Última modificación:
16/07/2026