Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2016-20066

Fecha de publicación:
15/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** WordPress CP Polls 1.0.8 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unsanitized file upload functionality. Attackers can upload files containing script payloads with event handlers like onerror attributes to execute arbitrary JavaScript in the browsers of users viewing the affected content.
Gravedad CVSS v4.0: MEDIA
Última modificación:
17/06/2026

CVE-2026-49757

Fecha de publicación:
15/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users via OAuth2/OIDC sign-in.<br /> <br /> AshAuthentication&amp;#39;s OAuth2 and OIDC family strategies matched the local user by email address (an upsert on the email field, or a user-defined sign-in filter) rather than by the OpenID Connect iss/sub claim combination. Per OpenID Connect Core §5.7, only iss/sub uniquely and stably identifies an end-user; other claims, including email, MUST NOT be used as unique identifiers.<br /> <br /> A provider login presenting a victim&amp;#39;s email, including an unverified email, a reused email, or an account with email_verified: false, resolved to and signed in as the victim&amp;#39;s existing local account. An unauthenticated attacker who can register an account on any accepted OAuth provider with the victim&amp;#39;s email (or who benefits from provider-side email reuse or reclamation) obtains the victim&amp;#39;s full local privileges.<br /> <br /> The fix resolves users by the (strategy, sub) identity stored in a user identity resource, and only links a new sub to an existing local account by email when the provider&amp;#39;s email_verified claim is trusted (trust_email_verified?).<br /> <br /> This issue affects ash_authentication from 0.1.0 before 4.14.0 and from 5.0.0-rc.0 before 5.0.0-rc.10.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
15/06/2026

CVE-2026-34026

Fecha de publicación:
15/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a path traversal vulnerability in the documentName parameter of the /safe/selfservice/openselfservicedocument endpoint. The application constructs a file path using attacker-controlled input without sufficient validation, allowing an authenticated attacker with any role or permission level to traverse out of the intended document directory and download arbitrary files accessible to the application. This includes, but is not limited to, application log files containing sensitive information and application binaries.
Gravedad CVSS v4.0: ALTA
Última modificación:
15/06/2026

CVE-2026-34027

Fecha de publicación:
15/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains insufficient server-side file type validation in the /safe/contract/uploadcustomdocuments endpoint. The application validates uploaded files based on the user-controlled HTTP Content-Type value and accepts the upload if this value contains an allowed string such as pdf, jpeg, tiff, or png. An authenticated attacker with any role or permission level can spoof the Content-Type value and upload arbitrary file content.
Gravedad CVSS v4.0: MEDIA
Última modificación:
15/06/2026

CVE-2026-34028

Fecha de publicación:
15/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, exposes web-accessible file paths that are not protected by an authorization scheme. An unauthenticated attacker can directly access HTTP endpoints to download files from locations such as /Resources/CompanyId_[ID]/Audio/ and /SafeData/.
Gravedad CVSS v4.0: MEDIA
Última modificación:
15/06/2026

CVE-2026-34029

Fecha de publicación:
15/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a hard-coded cryptographic key in the SafeSystem.Infrastructure.Security.dll component. An attacker with access to the application files can reverse engineer the DLL and recover the hard-coded cryptographic key. This key can be used to decrypt the licence.whs file, which contains sensitive information about the licensing party and a second key that can be used to decrypt other configuration files.
Gravedad CVSS v4.0: MEDIA
Última modificación:
15/06/2026

CVE-2026-34030

Fecha de publicación:
15/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, does not sufficiently validate the branch code when a new branch is created. The branch code is later used in multiple application functions, including filesystem path generation for uploaded files, profile pictures, and settings. An authenticated attacker with the settings_branches_manage privilege can include path traversal sequences in the branch code and influence the final filesystem location used by affected file operations. This can allow files to be stored in unintended locations, subject to service-account write permissions and branch-code length restrictions.
Gravedad CVSS v4.0: MEDIA
Última modificación:
15/06/2026

CVE-2026-5482

Fecha de publicación:
15/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Responsive FileManager&amp;#39;s allows an unauthenticated attacker to upload files of any type and extension without restriction using dialog.php endpoint, leading to Remote Code Execution. <br /> <br /> This project is unmaintained at the time of CVE assignment. The vulnerability was found in the latest release 9.14.0
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
16/06/2026

CVE-2026-34021

Fecha de publicación:
15/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485 communication between the server and the microcontroller without cryptographic protection. An attacker with access to the communication path between the server and the microcontroller can sniff RS-485 messages and replay previously observed messages. This can be used, for example, to spoof a "quit alarm" message and continuously deactivate the safe alarm.
Gravedad CVSS v4.0: ALTA
Última modificación:
15/06/2026

CVE-2026-34022

Fecha de publicación:
15/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Wertheim SafeController Family 65000, Controller 65000 - AssemblyVersion 6.11.8130.22319, uses weak custom cryptographic algorithms with hard-coded cryptographic keys to protect communication. An attacker in an adversary-in-the-middle position can decrypt the data traffic. During reassessment, it was possible to break the encryption/decryption routine and decrypt messages without knowledge of the encryption key. It was also possible to gain knowledge about the encryption key by intercepting enough messages.
Gravedad CVSS v4.0: ALTA
Última modificación:
15/06/2026

CVE-2026-34023

Fecha de publicación:
15/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an incorrect authorization vulnerability in the WebSocket communication used by the SafeController WebMessageBroker. An authenticated attacker with valid low-privileged branch user credentials can manipulate WebSocket messages by specifying controller identifiers belonging to other branches. This allows the attacker to access restricted functions and resources in other branches, including activating boxes outside of the user&amp;#39;s authorized branch.
Gravedad CVSS v4.0: ALTA
Última modificación:
15/06/2026

CVE-2026-34024

Fecha de publicación:
15/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains missing authorization checks on multiple web application endpoints. An authenticated attacker with minimal privileges can access endpoints that are not visible in the frontend but remain directly reachable. This allows the attacker to perform restricted actions such as switching the user&amp;#39;s branch, uploading arbitrary files, downloading arbitrary files, and viewing details of arbitrary branches.
Gravedad CVSS v4.0: ALTA
Última modificación:
15/06/2026