Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-87118

Fecha de publicación:
24/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality. An authenticated attacker with adjacent network access could submit crafted command data that corrupts memory, potentially disrupting authentication state or causing the affected process to terminate and the device to restart, resulting in a temporary denial of service.
Gravedad CVSS v4.0: MEDIA
Última modificación:
25/09/2026

CVE-2026-84403

Fecha de publicación:
24/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. An unauthenticated attacker within Bluetooth range could intercept or directly retrieve sensitive device information, including device identifiers, firmware information, and protected WiFi credentials.
Gravedad CVSS v4.0: MEDIA
Última modificación:
25/09/2026

CVE-2026-82585

Fecha de publicación:
24/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network could obtain stored recordings, live video, location information, images, diagnostic logs, or other sensitive information exchanged between the device and its mobile application.
Gravedad CVSS v4.0: ALTA
Última modificación:
25/09/2026

CVE-2026-82708

Fecha de publicación:
24/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a crafted request to access files within the device's removable storage that were not intended to be directly accessible through the web server. Exposed files could include recordings, images, diagnostic logs, or firmware files.
Gravedad CVSS v4.0: ALTA
Última modificación:
25/09/2026

CVE-2026-82716

Fecha de publicación:
24/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process. These logs remain accessible on removable storage after the support operation has completed. An unauthenticated attacker with physical access to the storage media could retrieve the logs and obtain sensitive device information.
Gravedad CVSS v4.0: MEDIA
Última modificación:
25/09/2026

CVE-2026-81630

Fecha de publicación:
24/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of a trusted cryptographic signature. A suitably positioned attacker who intercepts a firmware download, or an authenticated attacker who submits a crafted update, could install modified firmware and execute unauthorized code on the device.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
25/09/2026

CVE-2026-79959

Fecha de publicación:
24/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical access to the device could recover the credential and use it to obtain root access through the UART interface.
Gravedad CVSS v4.0: ALTA
Última modificación:
25/09/2026

CVE-2026-75558

Fecha de publicación:
24/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who obtains the protected credential and extracts the cryptographic material from the firmware could recover the WiFi password and gain unauthorized access to the device network.
Gravedad CVSS v4.0: MEDIA
Última modificación:
25/09/2026

CVE-2026-14443

Fecha de publicación:
24/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extension switch pre-shared keys to be written to system logs. Individuals with read access to container logs or support archives can obtain these keys, leading to the potential compromise of encrypted network tunnels.
Gravedad CVSS v4.0: ALTA
Última modificación:
25/09/2026

CVE-2026-14442

Fecha de publicación:
24/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be written to application logs in plain text. When scheduled support save jobs or related operational tasks are executed, sensitive parameters including external server passwords and archive protection keys are logged without proper masking. A local or authenticated user with access to application logs or support bundles can view these cleartext credentials, potentially leading to unauthorized access to remote backup targets or protected archives.
Gravedad CVSS v4.0: MEDIA
Última modificación:
25/09/2026

CVE-2026-14441

Fecha de publicación:
24/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A logic flaw in Java cache key handling object comparison handling could lead to improper identifier resolution when processing specific user account structures. The issue has been remediated by updating the internal comparison routines to ensure accurate object evaluation and prevent potential identity mismatch conditions.
Gravedad CVSS v4.0: MEDIA
Última modificación:
25/09/2026

CVE-2026-97365

Fecha de publicación:
24/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was determined in chonkie-inc littrs 0.6.1/0.6.2. Impacted is the function Sandbox::mount of the file crates/littrs/src/lib.rs. Executing a manipulation of the argument relative can lead to path traversal. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Gravedad CVSS v4.0: BAJA
Última modificación:
24/09/2026