Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-47882

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed application. This secret was generated using a non-cryptographic pseudo-random number generator rather than a cryptographically secure source of randomness.<br /> Affected Spring Products and Versions:<br /> Spring Tools for Eclipse: 5.2.0 and earlier
Gravedad CVSS v3.1: ALTA
Última modificación:
01/08/2026

CVE-2026-16530

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in the `pmLogLoadInDom()` function by sending a specially crafted request. This bypasses a critical bounds check, which can lead to the `pmproxy` service crashing, causing a Denial of Service (DoS). Additionally, this flaw may enable the leakage of sensitive information from the system&amp;#39;s memory.
Gravedad CVSS v3.1: MEDIA
Última modificación:
30/07/2026

CVE-2026-16531

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.
Gravedad CVSS v3.1: MEDIA
Última modificación:
30/07/2026

CVE-2026-16524

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A command injection flaw in PCP&amp;#39;s linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric.<br /> This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
Gravedad CVSS v3.1: ALTA
Última modificación:
04/08/2026

CVE-2026-16526

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw in the PCP linux_sockets module exposes an unsecured internal connection.<br /> An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.
Gravedad CVSS v3.1: ALTA
Última modificación:
04/08/2026

CVE-2026-16529

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.
Gravedad CVSS v3.1: ALTA
Última modificación:
04/08/2026

CVE-2026-16527

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
Gravedad CVSS v3.1: ALTA
Última modificación:
07/08/2026

CVE-2026-15255

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the identity being requested before returning front-end form submissions, allowing unauthenticated attackers to read other users&amp;#39; form submission data, including personal information.
Gravedad CVSS v3.1: MEDIA
Última modificación:
30/07/2026

CVE-2026-15257

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing action, allowing unauthenticated attackers to overwrite other users&amp;#39; form submissions and the profile fields of the associated non-administrator WordPress accounts.
Gravedad CVSS v3.1: MEDIA
Última modificación:
30/07/2026

CVE-2026-15382

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site&amp;#39;s custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site&amp;#39;s custom icon fonts with a single request.
Gravedad CVSS v3.1: MEDIA
Última modificación:
30/07/2026

CVE-2026-14923

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a REST route that creates and updates posts, because of an operator-precedence flaw in its authorization check. An authenticated user holding only the post-editing capability (such as a Contributor) can create, publish, and overwrite arbitrary Pages, including modifying content authored by higher-privileged users.
Gravedad CVSS v3.1: MEDIA
Última modificación:
30/07/2026

CVE-2026-15240

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the operator who initiated it, allowing a lower-privileged account that an operator is currently switched into to be resolved as that operator and to switch into any permitted account, including an administrator, resulting in full account takeover.
Gravedad CVSS v3.1: ALTA
Última modificación:
30/07/2026