Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-12901

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2026-13399

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments
Gravedad CVSS v3.1: ALTA
Última modificación:
07/08/2026

CVE-2026-13342

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-based login restriction feature, allowing the restriction to be bypassed so that unauthenticated requests from non-allowlisted IP addresses can reach and use the login form, defeating the access control the administrator configured.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2026-12584

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own orders without paying.
Gravedad CVSS v3.1: ALTA
Última modificación:
07/08/2026

CVE-2026-11361

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license delivery, and membership activation — without being charged.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2026-11803

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Gravedad CVSS v3.1: ALTA
Última modificación:
21/08/2026

CVE-2026-10524

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price when items are added to the cart through one of its public REST API endpoints, allowing unauthenticated users to set arbitrary product prices and complete WooCommerce orders at manipulated totals.
Gravedad CVSS v3.1: ALTA
Última modificación:
07/08/2026

CVE-2026-10599

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to reuse a single valid transaction to mark arbitrary orders as paid and bypass payment.
Gravedad CVSS v3.1: ALTA
Última modificación:
07/08/2026

CVE-2025-6508

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to be loaded, overriding the existing API definitions within the Publisher portal.<br /> <br /> By exploiting this vulnerability, malicious actors can deceive users into interacting with these overwritten API definitions. This could lead to the exposure of sensitive information or the initiation of unintended requests to backend services.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2025-15674

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through the WordPress core REST API when global protection is enabled, allowing any Contributor or higher to read the content of protected pages and posts without knowing the password.
Gravedad CVSS v3.1: BAJA
Última modificación:
07/08/2026

CVE-2025-12317

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user.<br /> <br /> This vulnerability could allow users to retain their previous access privileges even after their roles have been revoked. As a result, a user can continue to perform unauthorized actions or access restricted resources until the expired tokens naturally expire.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2025-14561

Fecha de publicación:
06/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants.<br /> <br /> The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
07/08/2026