Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-48051

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, Papra's webhook delivery system contains an SSRF protection bypass that allows any authenticated organisation member to cause the server to make HTTP requests to internal addresses — loopback, link-local, and RFC-1918 ranges. The SSRF protection validates the registered webhook URL but ignores redirect destinations. The HTTP client (ofetch) follows 3xx responses automatically, and the redirect target is never checked against the blocklist. An attacker registers a webhook pointing to an attacker-controlled server, which redirects incoming POSTs to any internal address. Exploitation was confirmed by live test against the official Docker image. The fix is a single-line change to the webhook HTTP client. This issue has been patched in version 26.5.0.
Gravedad CVSS v3.1: BAJA
Última modificación:
27/07/2026

CVE-2026-48052

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who is a member of any organization can delete or rename tags belonging to a different organization, given the target tag's ID. The route handler verifies the caller's membership of the ":organizationId" in the URL, but the repository write filters on tag.id alone, so the URL-level org scope never reaches the database. This issue has been patched in version 26.5.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/07/2026

CVE-2026-48030

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the terminal action handler allows any authenticated user to execute arbitrary OS commands by injecting shell metacharacters into the 'dir' POST parameter, completely bypassing the TERMINAL_COMMANDS whitelist and achieving full Remote Code Execution with web server privileges. This issue has been patched in version 2.0.4.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
27/07/2026

CVE-2026-17552

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call.<br /> <br /> When the rewrite base is a plain string, the REQUEST_URI is appended to it, with no check that the path starts with a forward slash (&amp;#39;/&amp;#39;).<br /> <br /> When the rewrite base does not contain a path (which is the standard given in the SYNOPSIS), an attacker can create a request that changes the hostname. A request target starting with an at-sign (&amp;#39;@&amp;#39;) changes the base to a RFC 3986 userinfo component.<br /> <br /> For example, a rewrite base of "https://example.com" with the submitted request "GET @192.168.1.2/" will send a request to "https://example.com@192.168.1.2/", with the rendered content returned to the attacker.<br /> <br /> This allows an attacker to access internal or restricted hosts that only the webserver has access to.
Gravedad: Pendiente de análisis
Última modificación:
27/07/2026

CVE-2026-17568

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request.<br /> <br /> This issue affects :<br /> <br /> * Devolutions Server 2026.2.4.0 through 2026.2.12.0<br /> * Devolutions Server 2026.1.23.0 and earlier
Gravedad: Pendiente de análisis
Última modificación:
27/07/2026

CVE-2026-17569

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint.<br /> <br /> This issue affects :<br /> <br /> * Devolutions Server 2026.2.4.0 through 2026.2.12.0<br /> * Devolutions Server 2026.1.23.0 and earlier
Gravedad: Pendiente de análisis
Última modificación:
27/07/2026

CVE-2026-17570

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests.<br /> <br /> This issue affects :<br /> <br /> * Devolutions Server 2026.2.4.0 through 2026.2.12.0<br /> * Devolutions Server 2026.1.23.0 and earlier
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/07/2026

CVE-2026-66729

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows unauthenticated remote attackers to crash the server process by sending a crafted Content-Disposition header with an empty field name. Attackers can trigger a uint32_t wraparound in http_mime_parser.h causing an out-of-bounds memory read past the name pointer, resulting in a bus fault that crashes the handling worker with a single POST request.
Gravedad CVSS v4.0: ALTA
Última modificación:
27/07/2026

CVE-2026-66731

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser that allows unauthenticated remote attackers to crash the server by sending a negative chunk size value. Attackers can send a single POST request with a Transfer-Encoding: chunked header containing a leading minus sign in the chunk size field, causing the parser in http1_parser.h to compute a large positive integer from the negated value, corrupting internal state and moving the read pointer into unmapped memory resulting in a fault.
Gravedad CVSS v4.0: ALTA
Última modificación:
27/07/2026

CVE-2026-66730

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unauthenticated remote attacker to permanently freeze worker processes at 100% CPU by sending a multipart/form-data request with a partial closing boundary. The missing progress guard in the parser loop causes http_mime_parse to return 0 bytes consumed without setting done or error flags, causing the calling loop to re-invoke the parser on the same buffer indefinitely, exhausting all workers and permanently disabling the server until manually restarted.
Gravedad CVSS v4.0: ALTA
Última modificación:
27/07/2026

CVE-2026-66390

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Neutralization of Input During Web Page Generation (&amp;#39;Cross-site Scripting&amp;#39;) vulnerability in Apache Wicket.<br /> <br /> This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0.<br /> <br /> Users are recommended to upgrade to version 10.10.0, which fixes the issue.
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/07/2026

CVE-2026-66391

Fecha de publicación:
27/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket.<br /> <br /> This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0.<br /> <br /> Users are recommended to upgrade to version 10.10.0, which fixes the issue.
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/07/2026