Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-19058

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was found in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function DataInterpreter of the file metagpt/roles/di/data_interpreter.py. The manipulation results in code injection. The attack must be initiated from a local position. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Gravedad CVSS v4.0: BAJA
Última modificación:
12/08/2026

CVE-2026-19059

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. This affects the function read of the file metagpt/tools/libs/editor.py. This manipulation causes path traversal. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Gravedad CVSS v4.0: BAJA
Última modificación:
12/08/2026

CVE-2026-18367

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
07/08/2026

CVE-2026-18487

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:80@attacker.com/](https://trusted.com:80@attacker.com/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2026-17032

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
07/08/2026

CVE-2026-16619

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a client-supplied identifier that is reissued on every login, allowing an attacker who already knows a user's password to guess the one-time code without limit and take over the account.
Gravedad CVSS v3.1: ALTA
Última modificación:
07/08/2026

CVE-2026-16620

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in "Select" price mode, allowing an unauthenticated visitor to add such a product to the cart at an arbitrary value below the merchant-defined allowed prices and commit a real order at that price (revenue loss / underpriced orders). This is a distinct, unfixed vector from CVE-2025-12115, whose 2.2.0 fix only addressed applying a custom price to products where Name Your Price is disabled and left the Select-mode allowlist unenforced through 2.2.4.
Gravedad CVSS v3.1: ALTA
Última modificación:
07/08/2026

CVE-2026-15256

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes registered on the site when a form so configured is embedded on a public page.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2026-16067

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non-WooCommerce) checkout, trusting the per-ticket price supplied by the client instead of re-deriving the event's configured price. This allows unauthenticated users to book paid event tickets for free, obtaining completed bookings and valid tickets at no cost.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2026-15732

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated attackers to make arbitrary HTTP requests and retrieve responses.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
07/08/2026

CVE-2026-15734

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary code as root.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
07/08/2026

CVE-2026-15733

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
07/08/2026