Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-66339

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information disclosure.
Gravedad CVSS v3.1: MEDIA
Última modificación:
28/07/2026

CVE-2026-66337

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client application to crash or disclose sensitive heap memory.
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/07/2026

CVE-2026-60135

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An attacker can modify data that should be restricted to read‑only access.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/07/2026

CVE-2026-61886

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Weintek cMT3092X HMI stores user account passwords in plaintext.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/07/2026

CVE-2026-61892

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/07/2026

CVE-2026-16280

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical memory, resulting in memory corruption or information disclosure.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
28/07/2026

CVE-2026-60134

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/07/2026

CVE-2026-55985

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The web management interface in <br /> Tycon Systems TPDIN-Monitor-WEB2<br /> <br /> stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.
Gravedad CVSS v4.0: MEDIA
Última modificación:
30/07/2026

CVE-2026-61884

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The web management interface of Tycon Systems TPDIN-Monitor-WEB2<br /> <br />  does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, device reboot, remote access service configuration, and network settings, which could allow an attacker to disrupt connected infrastructure or cause physical damage to equipment.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
30/07/2026

CVE-2025-71408

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lookup and executes arbitrary code including OS commands via the os module.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/07/2026

CVE-2026-66040

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution.
Gravedad CVSS v4.0: ALTA
Última modificación:
29/07/2026

CVE-2026-66041

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution.
Gravedad CVSS v4.0: ALTA
Última modificación:
29/07/2026