Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-14327

Fecha de publicación:
03/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires an attacker to first obtain a valid nonce and secure nonce via the publicly accessible ar_get_fresh_nonce and ar_process_user_image nopriv AJAX handlers, and to reproduce the encryption key locally — both steps are fully achievable by an unauthenticated attacker on any default free or unlicensed installation where ar_licence_key is unset.
Gravedad CVSS v3.1: ALTA
Última modificación:
06/07/2026

CVE-2026-12731

Fecha de publicación:
03/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sectionTitleTag' and 'articleTitleTag' Block Attributes in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/07/2026

CVE-2026-12729

Fecha de publicación:
03/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.3.0. This is due to a missing capability check on the do_migration() function registered as the wedocs_migrate_betterdocs_to_wedocs AJAX action, which performs no nonce verification via check_ajax_referer() and no capability check via current_user_can() before executing sensitive operations. This makes it possible for authenticated attackers, with Subscriber-level access and above, to trigger a full BetterDocs-to-weDocs data migration, creating and modifying 'docs' custom post type entries with attacker-controlled titles, updating site options, and deactivating the BetterDocs and BetterDocs Pro plugins via deactivate_plugins().
Gravedad CVSS v3.1: MEDIA
Última modificación:
06/07/2026

CVE-2026-13768

Fecha de publicación:
03/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key also allows a malicious user to execute arbitrary commands on a specific connected device and may allow the malicious user to pivot to other devices on the user's network.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
06/07/2026

CVE-2026-54477

Fecha de publicación:
03/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks.
Gravedad CVSS v4.0: MEDIA
Última modificación:
06/07/2026

CVE-2026-55726

Fecha de publicación:
03/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious user would be able to access any device log file available in the blob storage container.
Gravedad CVSS v4.0: MEDIA
Última modificación:
06/07/2026

CVE-2026-13722

Fecha de publicación:
03/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. An authenticated administrator can exploit this vulnerability to install a tampered firmware image.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/08/2026

CVE-2026-13728

Fecha de publicación:
03/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources.<br /> <br /> This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster.
Gravedad CVSS v4.0: MEDIA
Última modificación:
28/08/2026

CVE-2026-8247

Fecha de publicación:
03/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local network segment to execute arbitrary code.<br /> <br /> <br /> <br /> <br /> This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/08/2026

CVE-2026-13371

Fecha de publicación:
03/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending malformed or crafted data to the put_data endpoint, which performs unsafe deserialization of the attacker-supplied input.
Gravedad CVSS v4.0: MEDIA
Última modificación:
28/08/2026

CVE-2026-13373

Fecha de publicación:
03/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Neutralization of Input During Web Page Generation (XSS or &amp;#39;Cross-site Scripting&amp;#39;) vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13936.
Gravedad CVSS v4.0: MEDIA
Última modificación:
28/08/2026

CVE-2026-13374

Fecha de publicación:
03/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Neutralization of Input During Web Page Generation (XSS or &amp;#39;Cross-site Scripting&amp;#39;) vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13937.
Gravedad CVSS v4.0: MEDIA
Última modificación:
28/08/2026