Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-47831

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-builder allows a remote attacker to brute-force the resulting SSH login via TCP/22.<br /> Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.
Gravedad CVSS v4.0: ALTA
Última modificación:
09/07/2026

CVE-2026-47840

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during simple-bind authentication, and return forged group memberships that grant themselves admin scopes. This affects every deployment that authenticates users against LDAP over StartTLS.<br /> Affected versions: UAA versions prior to v78.13.0; Cf-deployment versions prior to v56.2.0.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
09/07/2026

CVE-2026-47829

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator&amp;#39;s workstation.<br /> Affected versions: bosh-cli versions prior to v7.10.4.
Gravedad CVSS v4.0: ALTA
Última modificación:
13/07/2026

CVE-2026-11875

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session cookie, allowing unauthenticated attackers to forge it and impersonate any ticket owner (identified by email address) to read, reply to, and close that person&amp;#39;s support tickets.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-12270

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belonging to its onboarding assistant: the capability check is only applied when an attacker-controllable request header holds a specific value, so it can be bypassed by omitting or changing that header. This makes it possible for unauthenticated attackers to read onboarding status information, modify the related Everest Forms WordPress plugin before 3.5.0 options, and trigger an email from the site to an arbitrary address.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-12516

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated media-proxying endpoint, allowing anonymous users to make the site fetch arbitrary URLs, including internal and private-network addresses, and read back the response body. This results in a full-read Server-Side Request Forgery and open proxy.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-12517

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated site-info endpoint before fetching it, allowing anonymous users (the gating nonce is exposed on public pages carrying an embed) to make the site request internal and private-network URLs and read back the parsed page metadata. This is a Server-Side Request Forgery.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-47828

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM&amp;#39;s DAV blobstore over HTTPS without verifying the server certificate, even though a CA certificate for that endpoint is available in the installation manifest. A network attacker can terminate the TLS connection, harvest the Basic-auth credentials, and read the rendered-templates archive containing every bootstrap secret for the new BOSH Director, then replay the credentials against the real VM&amp;#39;s agent for root code execution.<br /> Affected versions: bosh-cli versions prior to v7.10.4.
Gravedad CVSS v4.0: ALTA
Última modificación:
13/07/2026

CVE-2026-47826

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information.<br /> Affected versions: BOSH CLI tool versions prior to v7.10.4.
Gravedad CVSS v4.0: ALTA
Última modificación:
13/07/2026

CVE-2026-11571

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other users&amp;#39; form submission records via predictable, enumerable filenames.
Gravedad CVSS v3.1: ALTA
Última modificación:
09/07/2026

CVE-2026-11869

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-processing path of its data subject access request feature, allowing unauthenticated attackers to generate and download the full personal-data export (including name, postal address, phone number, email, and comment content) of any user, customer, or commenter by supplying their email address.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-5523

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.8. This is due to the update_user() function accepting a user ID parameter from form submissions without verifying that the authenticated user has permission to edit that specific user account, and the handle_register_submission() function only checking if any user is logged in rather than validating permissions for the target user. This makes it possible for authenticated attackers, with subscriber-level access and above, to change the email address and password of any user account, including administrators, resulting in complete account takeover.
Gravedad CVSS v3.1: ALTA
Última modificación:
09/07/2026