Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-57723

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine &amp; PMS allows Path Traversal.<br /> <br /> This issue affects VikBooking Hotel Booking Engine &amp; PMS: from n/a through 1.8.12.
Gravedad CVSS v3.1: ALTA
Última modificación:
01/07/2026

CVE-2026-57736

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data.<br /> <br /> This issue affects HubSpot: from n/a through 11.3.51.
Gravedad CVSS v3.1: ALTA
Última modificación:
01/07/2026

CVE-2026-57737

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Neutralization of Input During Web Page Generation (&amp;#39;Cross-site Scripting&amp;#39;) vulnerability in Averta LTD Shortcodes and extra features for Phlox theme allows DOM-Based XSS.<br /> <br /> This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.17.16.
Gravedad CVSS v3.1: MEDIA
Última modificación:
02/07/2026

CVE-2026-57722

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Neutralization of Input During Web Page Generation (&amp;#39;Cross-site Scripting&amp;#39;) vulnerability in ShortPixel Enable Media Replace allows Stored XSS.<br /> <br /> This issue affects Enable Media Replace: from n/a through 4.2.1.
Gravedad CVSS v3.1: MEDIA
Última modificación:
02/07/2026

CVE-2026-49091

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forging (CAPEC-93). An attacker can supply specially crafted input that is written to log files without proper neutralization. When the log files are subsequently viewed in a terminal that interprets control sequences, the injected content may alter the displayed log data.
Gravedad CVSS v3.1: ALTA
Última modificación:
02/07/2026

CVE-2026-51946

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** SQL Injection vulnerability in GoAdminGroup GoAdmin (last release v1.2.26) allows a remote attacker to execute arbitrary code and obtain sensitive information via the the __sort_type URL parameter on all /admin/info/{table} endpoints
Gravedad CVSS v3.1: MEDIA
Última modificación:
02/07/2026

CVE-2026-54428

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.
Gravedad CVSS v3.1: ALTA
Última modificación:
24/07/2026

CVE-2026-49090

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted bulk request that causes sustained high CPU consumption, which can render the affected node unable to process requests.
Gravedad CVSS v3.1: MEDIA
Última modificación:
02/07/2026

CVE-2026-46680

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.
Gravedad CVSS v4.0: ALTA
Última modificación:
03/07/2026

CVE-2026-58452

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by supplying a malicious Wireless parameter to the HTTP PUT NetSDK/Factory SetMAC endpoint. Attackers can craft a string beginning with a valid MAC-like prefix followed by a semicolon and a shell payload, which bypasses partial sscanf() validation and is passed unsanitized into an echo shell command executed through a system() wrapper.
Gravedad CVSS v4.0: ALTA
Última modificación:
02/07/2026

CVE-2026-58453

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent attackers to gain unauthorized access by using the default admin username with an empty password accepted by the anyka_ipc HTTP service on port 80. Attackers can authenticate with these hardcoded credentials to access camera snapshots, video streams, network configuration, and factory-level API endpoints including the SetMAC command injection surface.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
02/07/2026

CVE-2026-58454

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a remote code execution vulnerability that allows authenticated attackers to execute arbitrary shell scripts by writing to the writable persistent JFFS2 storage path and triggering execution through the authenticated HTTP endpoint. Attackers can stage a malicious script in the writable persistent storage and request the config endpoint to invoke it via popen(), achieving persistent remote code execution that survives device reboots.
Gravedad CVSS v4.0: ALTA
Última modificación:
02/07/2026