Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-58521

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper neutralization of special elements used in an SQL command (&amp;#39;SQL injection&amp;#39;) vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection.<br /> <br /> This issue affects Mediawiki - Cargo Extension: from * before 1.43.9,1.44.6,1.45.4.
Gravedad CVSS v4.0: MEDIA
Última modificación:
07/07/2026

CVE-2026-58520

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** URL redirection to untrusted site (&amp;#39;open redirect&amp;#39;) vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener Extension allows Cross-Site Flashing.<br /> <br /> This issue affects Mediawiki - UrlShortener Extension: from * before 1.43.9, 1.44.6, 1.45.4.
Gravedad CVSS v4.0: MEDIA
Última modificación:
09/07/2026

CVE-2026-57723

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine &amp; PMS allows Path Traversal.<br /> <br /> This issue affects VikBooking Hotel Booking Engine &amp; PMS: from n/a through 1.8.12.
Gravedad CVSS v3.1: ALTA
Última modificación:
01/07/2026

CVE-2026-57736

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data.<br /> <br /> This issue affects HubSpot: from n/a through 11.3.51.
Gravedad CVSS v3.1: ALTA
Última modificación:
01/07/2026

CVE-2026-57737

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Neutralization of Input During Web Page Generation (&amp;#39;Cross-site Scripting&amp;#39;) vulnerability in Averta LTD Shortcodes and extra features for Phlox theme allows DOM-Based XSS.<br /> <br /> This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.17.16.
Gravedad CVSS v3.1: MEDIA
Última modificación:
02/07/2026

CVE-2026-57722

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Neutralization of Input During Web Page Generation (&amp;#39;Cross-site Scripting&amp;#39;) vulnerability in ShortPixel Enable Media Replace allows Stored XSS.<br /> <br /> This issue affects Enable Media Replace: from n/a through 4.2.1.
Gravedad CVSS v3.1: MEDIA
Última modificación:
02/07/2026

CVE-2026-49091

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forging (CAPEC-93). An attacker can supply specially crafted input that is written to log files without proper neutralization. When the log files are subsequently viewed in a terminal that interprets control sequences, the injected content may alter the displayed log data.
Gravedad CVSS v3.1: ALTA
Última modificación:
02/07/2026

CVE-2026-51946

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** SQL Injection vulnerability in GoAdminGroup GoAdmin (last release v1.2.26) allows a remote attacker to execute arbitrary code and obtain sensitive information via the the __sort_type URL parameter on all /admin/info/{table} endpoints
Gravedad CVSS v3.1: MEDIA
Última modificación:
02/07/2026

CVE-2026-54428

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.
Gravedad CVSS v3.1: ALTA
Última modificación:
24/07/2026

CVE-2026-49090

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted bulk request that causes sustained high CPU consumption, which can render the affected node unable to process requests.
Gravedad CVSS v3.1: MEDIA
Última modificación:
02/07/2026

CVE-2026-46680

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.
Gravedad CVSS v4.0: ALTA
Última modificación:
03/07/2026

CVE-2026-58452

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by supplying a malicious Wireless parameter to the HTTP PUT NetSDK/Factory SetMAC endpoint. Attackers can craft a string beginning with a valid MAC-like prefix followed by a semicolon and a shell payload, which bypasses partial sscanf() validation and is passed unsanitized into an echo shell command executed through a system() wrapper.
Gravedad CVSS v4.0: ALTA
Última modificación:
02/07/2026