Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-16551

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation.<br /> <br /> <br /> This issue affects OpenCanary 0.9.8 only.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/07/2026

CVE-2025-13146

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The vulnerability was partially patched in version 5.0.4.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/07/2026

CVE-2026-16473

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory.
Gravedad CVSS v3.1: MEDIA
Última modificación:
30/07/2026

CVE-2026-14551

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the directory %ProgramData%\ServerEye3\update\ for a trigger file named "update_available". Due to insufficient access restrictions on this directory, a local standard user can create the trigger file and provide a path to a directory containing malicious JSON instructions. The service subsequently executes the utility UpdaterAction.exe with SYSTEM privileges, which parses the instructions and performs an unvalidated file copy from a user-controlled source to a protected system destination (e.g., overwriting a service binary). This leads to full system compromise as the service automatically restarts the overwritten binary with SYSTEM privileges.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-63264

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/07/2026

CVE-2026-2406

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. Online Registration and Workflow Management System allows Exploiting Trust in Client.<br /> <br /> This issue affects Online Registration and Workflow Management System: through 12022026.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/07/2026

CVE-2026-15787

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. wp_kses_post, applied on save for users without unfiltered_html, does not neutralize HTML-entity-encoded payloads stored inside data-* attributes on kses-allowed elements, as the browser decodes these values client-side before jQuery .html() renders them as markup.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/07/2026

CVE-2026-63048

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - joomlack.fr - Improper access control in Page Builder CK
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
23/07/2026

CVE-2026-63047

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/07/2026

CVE-2026-45820

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry declaring compressed_size=0xFFFFFFFF (ZIP64 sentinel) but missing the required ZIP64 extra field tag 0x0001 causes z64e() to loop indefinitely due to out-of-bounds reads returning undefined, which coerces to 0, keeping the loop condition permanently true.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/07/2026

CVE-2026-12987

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a booker-supplied registration field is stored as booking meta and later deserialized without restricting allowed classes, enabling PHP object injection. The resulting gadget chain reaches a database query that is built without parameterisation, so an unauthenticated attacker can read arbitrary database data (e.g. user password hashes, secret keys) when the booking is later loaded.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-14322

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making any payment.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/07/2026