Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-17541

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them.
Gravedad CVSS v3.1: ALTA
Última modificación:
10/08/2026

CVE-2026-17542

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents which may contain sensitive data.
Gravedad CVSS v3.1: ALTA
Última modificación:
10/08/2026

CVE-2026-18200

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user making the request, allowing authenticated users, with Subscriber-level access and above, to modify the profile details of arbitrary users, including administrators.
Gravedad CVSS v3.1: MEDIA
Última modificación:
11/08/2026

CVE-2026-17023

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature.
Gravedad CVSS v3.1: MEDIA
Última modificación:
11/08/2026

CVE-2026-17540

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service.
Gravedad CVSS v3.1: ALTA
Última modificación:
11/08/2026

CVE-2026-18030

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one of its form actions, allowing unauthenticated attackers to set an arbitrary password for any user, including administrators, and take over their account.<br /> <br /> Exploitation requires the site to have a form using the BricksForge WordPress plugin before 3.1.8.8&amp;#39;s password reset action in its update mode. The server-side current-password verification option for that action is disabled by default, so the vulnerable state is the default one once the action is used.
Gravedad CVSS v3.1: ALTA
Última modificación:
11/08/2026

CVE-2026-17020

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer&amp;#39;s booking personal data such as name, email, phone number, address and private notes by enumerating booking identifiers.
Gravedad CVSS v3.1: MEDIA
Última modificación:
13/08/2026

CVE-2026-17021

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.
Gravedad CVSS v3.1: MEDIA
Última modificación:
13/08/2026

CVE-2026-17022

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking&amp;#39;s ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers&amp;#39; booking records, including personal information, by supplying a sequential booking identifier.
Gravedad CVSS v3.1: ALTA
Última modificación:
13/08/2026

CVE-2026-17010

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before outputting them, allowing users with contributor-level access and above to inject stored Cross-Site Scripting payloads that execute in the browser of a higher-privileged user who reviews the content.
Gravedad CVSS v3.1: MEDIA
Última modificación:
10/08/2026

CVE-2026-17019

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and does not adequately restrict who can upload them, allowing unauthenticated attackers to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored Cross-Site Scripting).
Gravedad CVSS v3.1: MEDIA
Última modificación:
10/08/2026

CVE-2026-16298

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
11/08/2026