Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-56129

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control. A logged-in user with no administrative privilege may access physical memory.
Gravedad CVSS v4.0: MEDIA
Última modificación:
25/06/2026

CVE-2026-12245

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response.
Gravedad CVSS v4.0: ALTA
Última modificación:
26/06/2026

CVE-2026-12246

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes.
Gravedad CVSS v4.0: ALTA
Última modificación:
26/06/2026

CVE-2026-12490

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the tls-auth-port) or over over TCP over the regular port, when the other conditions of the provide-xfr rule match.
Gravedad CVSS v4.0: ALTA
Última modificación:
26/06/2026

CVE-2026-5305

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks
Gravedad CVSS v3.1: ALTA
Última modificación:
25/06/2026

CVE-2026-9702

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destination to be updated, allowing unauthenticated attackers to silently redirect the shipping destination of any pending or processing order on the site.
Gravedad CVSS v3.1: ALTA
Última modificación:
25/06/2026

CVE-2026-12244

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes
Gravedad CVSS v4.0: ALTA
Última modificación:
26/06/2026

CVE-2026-10824

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthenticated users to read and permanently delete any user's course-progress records.
Gravedad CVSS v3.1: MEDIA
Última modificación:
25/06/2026

CVE-2026-8330

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed sensitive information to be written to application logs due to insufficient filtering in a CI/CD API endpoint.
Gravedad CVSS v3.1: MEDIA
Última modificación:
26/06/2026

CVE-2026-5952

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to bypass package protection rules and overwrite protected Maven package metadata due to incorrect authorization checks.
Gravedad CVSS v3.1: MEDIA
Última modificación:
26/06/2026

CVE-2026-5796

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with Reporter-level group permissions to view package metadata from projects with the Package Registry disabled due to incorrect authorization checks in the group packages feature.
Gravedad CVSS v3.1: MEDIA
Última modificación:
26/06/2026

CVE-2026-5309

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to read or modify another group's virtual registry cleanup policy settings without authorization.
Gravedad CVSS v3.1: MEDIA
Última modificación:
26/06/2026