Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2025-7018

Fecha de publicación:
12/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Null pointer dereference vulnerability in Avira Antivirus engine when scanning a malformed Windows PE file may allow Denial-of-Service of the antivirus engine process.<br /> <br /> This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.64.
Gravedad CVSS v3.1: MEDIA
Última modificación:
12/06/2026

CVE-2025-7019

Fecha de publicación:
12/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Stack overflow vulnerability in Avast Antivirus when scanning a malformed Office Open XML file may allow Denial-of-Service of the antivirus process.<br /> <br /> This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds before VPS 25020100.<br /> <br /> <br /> <br /> The affected scanning logic is delivered through a shared Gen Digital virus definition update stream. The same stream feeds the consumer antivirus products listed in this advisory and other Gen Digital products that embed the same engine. Mitigation flows through this update channel; installations at or above the listed build are not vulnerable regardless of which product consumes the stream.
Gravedad CVSS v3.1: MEDIA
Última modificación:
12/06/2026

CVE-2026-12131

Fecha de publicación:
12/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** A weakness has been identified in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function Invoice of the file \application\controllers\Payroll.php of the component Payroll Invoice Module. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Gravedad CVSS v4.0: BAJA
Última modificación:
12/06/2026

CVE-2025-7002

Fecha de publicación:
12/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed PDF file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process.<br /> <br /> This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.68.
Gravedad CVSS v3.1: ALTA
Última modificación:
12/06/2026

CVE-2025-7003

Fecha de publicación:
12/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed PDF file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process.<br /> <br /> This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.56.
Gravedad CVSS v3.1: ALTA
Última modificación:
12/06/2026

CVE-2025-7004

Fecha de publicación:
12/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Heap buffer out-of-bounds write vulnerability in Avast Antivirus when scanning a malformed Windows PE file may allow Local Execution of Code or Denial-of-Service of the antivirus process.<br /> <br /> This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds before VPS 25040308.<br /> <br /> <br /> <br /> The affected scanning logic is delivered through a shared Gen Digital virus definition update stream. The same stream feeds the consumer antivirus products listed in this advisory and other Gen Digital products that embed the same engine. Mitigation flows through this update channel; installations at or above the listed build are not vulnerable regardless of which product consumes the stream.
Gravedad CVSS v3.1: ALTA
Última modificación:
12/06/2026

CVE-2025-7005

Fecha de publicación:
12/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Uncontrolled recursion vulnerability in Avast Antivirus when scanning a malformed Windows PE file may allow Denial-of-Service of the antivirus process.<br /> <br /> This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds before VPS 25031700.<br /> <br /> <br /> <br /> The affected scanning logic is delivered through a shared Gen Digital virus definition update stream. The same stream feeds the consumer antivirus products listed in this advisory and other Gen Digital products that embed the same engine. Mitigation flows through this update channel; installations at or above the listed build are not vulnerable regardless of which product consumes the stream.
Gravedad CVSS v3.1: MEDIA
Última modificación:
12/06/2026

CVE-2025-7006

Fecha de publicación:
12/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Use of stack memory after free vulnerability in Avast Antivirus when scanning a malformed Windows PE file may allow Denial-of-Service of the antivirus process.<br /> <br /> This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds before VPS 25022500.<br /> <br /> <br /> <br /> The affected scanning logic is delivered through a shared Gen Digital virus definition update stream. The same stream feeds the consumer antivirus products listed in this advisory and other Gen Digital products that embed the same engine. Mitigation flows through this update channel; installations at or above the listed build are not vulnerable regardless of which product consumes the stream.
Gravedad CVSS v3.1: MEDIA
Última modificación:
12/06/2026

CVE-2025-7008

Fecha de publicación:
12/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Windows PE file with .NET metadata may allow Local Execution of Code or Denial-of-Service of the antivirus process.<br /> <br /> This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds before VPS 25021310.<br /> <br /> <br /> <br /> The affected scanning logic is delivered through a shared Gen Digital virus definition update stream. The same stream feeds the consumer antivirus products listed in this advisory and other Gen Digital products that embed the same engine. Mitigation flows through this update channel; installations at or above the listed build are not vulnerable regardless of which product consumes the stream.
Gravedad CVSS v3.1: ALTA
Última modificación:
12/06/2026

CVE-2025-7009

Fecha de publicación:
12/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Windows PE file may allow Local Execution of Code or Denial-of-Service of the antivirus process.<br /> <br /> This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds before VPS 25021310.<br /> <br /> <br /> <br /> The affected scanning logic is delivered through a shared Gen Digital virus definition update stream. The same stream feeds the consumer antivirus products listed in this advisory and other Gen Digital products that embed the same engine. Mitigation flows through this update channel; installations at or above the listed build are not vulnerable regardless of which product consumes the stream.
Gravedad CVSS v3.1: ALTA
Última modificación:
12/06/2026

CVE-2020-2521

Fecha de publicación:
12/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rejected reason: This candidate was issued in error.
Gravedad: Pendiente de análisis
Última modificación:
12/06/2026

CVE-2026-54393

Fecha de publicación:
12/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** A stored cross-site scripting vulnerability exists in MISP when the Overmind theme is used. The setHomePage endpoint previously saved the user-controlled path value through setSettingInternal(), bypassing the normal setSetting() validation logic, including validate_homepage, which requires homepage paths to start with /. As a result, an authenticated user could store an arbitrary homepage value, including an XSS payload.<br /> <br /> The stored value was later rendered in app/View/News/index.ctp as the href attribute of the “Continue to homepage” link without HTML escaping. This could allow execution of attacker-controlled JavaScript in the browser context of the affected MISP instance when the crafted homepage link is rendered and interacted with.<br /> <br /> The issue is fixed by always persisting the homepage setting through setSetting(), ensuring validation and access checks are applied, and by HTML-escaping the homepage value before rendering it in the news view.
Gravedad CVSS v4.0: MEDIA
Última modificación:
12/06/2026