Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-14652

Fecha de publicación:
04/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown function of the file /admin/login.php of the component Admin Login. The manipulation of the argument Username results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
Gravedad CVSS v4.0: MEDIA
Última modificación:
06/07/2026

CVE-2024-1248

Fecha de publicación:
04/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to the federated user.<br /> <br /> Exploitation requires a federated identity provider (IDP) with silent JIT provisioning enabled and an attacker&amp;#39;s knowledge of a local user&amp;#39;s username. When these conditions are met, a malicious individual can leverage the JIT provisioning process to modify the roles of local users. The overwritten roles are limited to those defined within the federated IDP, typically granting minimal access rights unless explicitly configured otherwise by the federated IDP administrator.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-14650

Fecha de publicación:
04/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw has been found in connorskees grass up to 0.13.4. The affected element is the function grass_compiler::raw_to_parse_error of the component UTF-8 Character Handler. Executing a manipulation can lead to denial of service. The attack is restricted to local execution. The exploit has been published and may be used. In Issue #117 with similar structure the project maintainer explains: "DoS vulnerabilities are generally fine in Sass compilers -- they are trivially possible with recursive functions, infinite loops, nested mixins, etc. The description here is wrong. Compile time is not expected to be linear relative to the input, and the @extend algorithm is definitionally exponential."
Gravedad CVSS v4.0: BAJA
Última modificación:
06/07/2026

CVE-2026-14648

Fecha de publicación:
04/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A security vulnerability has been detected in code-projects Online Voting System up to 0.x/1.0. This issue affects the function test_input of the file /authentication.php of the component Login. Such manipulation of the argument adminUserName/adminPassword leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Gravedad CVSS v4.0: MEDIA
Última modificación:
06/07/2026

CVE-2026-14649

Fecha de publicación:
04/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was detected in code-projects Online Voting System 1.0. Impacted is the function test_input of the file /saveVote.php. Performing a manipulation of the argument voterName/voterEmail/voterID/selectedCandidate results in sql injection. The attack can be initiated remotely.
Gravedad CVSS v4.0: MEDIA
Última modificación:
07/07/2026

CVE-2026-14641

Fecha de publicación:
04/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit_course.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
Gravedad CVSS v4.0: MEDIA
Última modificación:
06/07/2026

CVE-2026-14642

Fecha de publicación:
04/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /edit_class2.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
Gravedad CVSS v4.0: MEDIA
Última modificación:
06/07/2026

CVE-2026-14640

Fecha de publicación:
04/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Gravedad CVSS v4.0: MEDIA
Última modificación:
06/07/2026

CVE-2026-14647

Fecha de publicación:
04/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A weakness has been identified in onnx up to 1.21.x. This vulnerability affects the function convPoolShapeInference_opset19 of the file onnx/defs/nn/old.cc of the component onnxruntime. This manipulation causes out-of-bounds read. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Patch name: a7bf3a0f1d18bb62575236ef6e4944980c40e045. It is recommended to apply a patch to fix this issue.
Gravedad CVSS v4.0: BAJA
Última modificación:
06/07/2026

CVE-2026-14638

Fecha de publicación:
04/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw has been found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /patient.php. This manipulation of the argument editid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
Gravedad CVSS v4.0: BAJA
Última modificación:
06/07/2026

CVE-2026-12740

Fecha de publicación:
04/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter.<br /> <br /> RequestTokenV2 builds the provider authorization redirect without issuing a state value, and AccessTokenV2 exchanges the callback code and registers the resulting token into the session (register_session) without verifying that the callback corresponds to an authorization request this session initiated.<br /> <br /> Any application that uses this middleware for OAuth 2.0 login is exposed to login cross-site request forgery: because the callback is not bound to the session that began the flow, an attacker who starts an authorization with their own provider account can deliver the resulting callback to a victim, causing the victim&amp;#39;s session to complete the attacker&amp;#39;s authorization and associating the attacker&amp;#39;s provider identity and access token with that session. Where the application persists this as an account link, the attacker may retain access to the victim&amp;#39;s account through their own provider credentials.
Gravedad CVSS v3.1: ALTA
Última modificación:
06/07/2026

CVE-2026-12746

Fecha de publicación:
04/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter.<br /> <br /> The authentication_url method builds the provider authorization redirect without issuing a state value, and the callback method exchanges the callback code and registers the resulting token into the session without verifying that the callback corresponds to an authorization request this session initiated.<br /> <br /> Any application that uses this plugin for OAuth 2.0 login is exposed to login cross-site request forgery: because the callback is not bound to the session that began the flow, an attacker who starts an authorization with their own provider account can deliver the resulting callback to a victim, causing the victim&amp;#39;s session to complete the attacker&amp;#39;s authorization and associating the attacker&amp;#39;s provider identity and access token with that session. Where the application persists this as an account link, the attacker may retain access to the victim&amp;#39;s account through their own provider credentials.
Gravedad CVSS v3.1: ALTA
Última modificación:
06/07/2026