Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-70619

Fecha de publicación:
04/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes that verify session authentication but omit the admin authorization guard. Attackers can supply an attacker-controlled URL to overwrite the embedding backend persisted in the endpoint configuration file and process environment, causing all subsequent embedding operations including chat messages, RAG queries, memory entries, and vault text to be transmitted in plaintext to the attacker-controlled destination, or delete the endpoint configuration to deny embedding service to all users.
Gravedad CVSS v4.0: ALTA
Última modificación:
05/08/2026

CVE-2026-67860

Fecha de publicación:
04/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memory backend.
Gravedad CVSS v3.1: ALTA
Última modificación:
05/08/2026

CVE-2026-67862

Fecha de publicación:
04/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. This allows a remote attacker to cause a denial of service.
Gravedad CVSS v3.1: ALTA
Última modificación:
05/08/2026

CVE-2026-67858

Fecha de publicación:
04/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 request containing many unique discoveryUrls. This allows remote attackers to cause a denial of service.
Gravedad CVSS v3.1: ALTA
Última modificación:
05/08/2026

CVE-2026-70589

Fecha de publicación:
04/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. This issue is fixed in version 6.54.1.
Gravedad CVSS v3.1: MEDIA
Última modificación:
05/08/2026

CVE-2026-70590

Fecha de publicación:
04/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the hashes could lead to account takeover if successful, but Device Verification should have prevented an attacker from logging in with a recovered password. Depending on the database used, leaked hashes may not have had the correct casing for all characters, increasing the difficulty of a password-guessing attack. This issue is fixed in version 6.54.1.
Gravedad CVSS v3.1: MEDIA
Última modificación:
05/08/2026

CVE-2026-70591

Fecha de publicación:
04/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was returned, but this could have been used to probe open ports on internal hosts. This issue is fixed in version 6.54.1.
Gravedad CVSS v3.1: MEDIA
Última modificación:
05/08/2026

CVE-2026-67859

Fecha de publicación:
04/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.
Gravedad CVSS v3.1: ALTA
Última modificación:
05/08/2026

CVE-2026-67861

Fecha de publicación:
04/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component
Gravedad CVSS v3.1: ALTA
Última modificación:
05/08/2026

CVE-2026-67855

Fecha de publicación:
04/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial of service.
Gravedad CVSS v3.1: ALTA
Última modificación:
05/08/2026

CVE-2026-67856

Fecha de publicación:
04/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(Sampling), Publish, TransferSubscriptions, and DeleteSubscriptions requests
Gravedad CVSS v3.1: ALTA
Última modificación:
05/08/2026

CVE-2026-52370

Fecha de publicación:
04/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.
Gravedad CVSS v3.1: MEDIA
Última modificación:
05/08/2026