Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-75798

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only features, relying instead on a token it hands out to anonymous visitors, allowing unauthenticated attackers to run AI queries of their own choosing against the site owner's configured provider account.
Gravedad CVSS v3.1: MEDIA
Última modificación:
26/08/2026

CVE-2026-19760

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WP Fastest Cache – WordPress Cache Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTTP Host Header in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the Polylang or Polylang Pro plugin to be active and the Combine JS option to be enabled, as these conditions trigger the vulnerable Host-header-to-URL code path that writes attacker-controlled script src values into the shared page-cache file served to all subsequent visitors.
Gravedad CVSS v3.1: ALTA
Última modificación:
26/08/2026

CVE-2026-74851

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its list of blocked functions, allowing users with the author role and above to execute arbitrary code on the server. Only sites using the restricted display-callback mode are affected, which is the automatic default on installations whose first Pods version predates 3.1.
Gravedad CVSS v3.1: ALTA
Última modificación:
26/08/2026

CVE-2026-74928

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its import routes, allowing unauthenticated users to create WordPress accounts with a password the attacker already knows, bypassing the site's own registration setting.
Gravedad CVSS v3.1: ALTA
Última modificación:
26/08/2026

CVE-2026-58093

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty lock, the handler did not revalidate the state of the terminal, and could proceed to link a terminal that was concurrently being destroyed to the calling process&amp;#39; session.<br /> <br /> An unprivileged local user can exploit this race condition to escalate privileges.
Gravedad CVSS v3.1: ALTA
Última modificación:
27/08/2026

CVE-2026-58094

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a largepage shared memory object. This is intended to be used immediately after creating the object, before any memory is allocated for the object. The handler checked whether a page size had already been configured without holding the rangelock. Two concurrent callers could both observe an unconfigured object and set conflicting page sizes, leaving the object in an inconsistent state.<br /> <br /> An unprivileged local user can exploit this race to escalate privileges.
Gravedad CVSS v3.1: ALTA
Última modificación:
27/08/2026

CVE-2026-58097

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface.<br /> <br /> A local user with access to the ppp(8) command interface can crash ppp(8) or potentially execute arbitrary code as root.
Gravedad CVSS v3.1: ALTA
Última modificación:
27/08/2026

CVE-2026-58095

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer.<br /> <br /> A malicious PPP peer can crash ppp(8) or potentially execute arbitrary code as root.
Gravedad CVSS v3.1: ALTA
Última modificación:
27/08/2026

CVE-2026-58096

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write.<br /> <br /> A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root.
Gravedad CVSS v3.1: ALTA
Última modificación:
27/08/2026

CVE-2026-15203

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, upload and execute unsigned applications, and upload unsigned EEPROM data and firmware via exposed service interfaces and software update mechanisms
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
26/08/2026

CVE-2026-14550

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation through its REST API, verifying only a publicly available nonce, allowing unauthenticated users to submit reservations with an arbitrary approval status and bypass the administrator moderation workflow.
Gravedad CVSS v3.1: MEDIA
Última modificación:
26/08/2026

CVE-2026-16984

Fecha de publicación:
26/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Privacy Policy Generator, Terms &amp; Conditions, GDPR, CCPA, Cookie Policy &amp; Disclaimer Templates WordPress plugin before 3.7.1 does not include an authorization check on a REST route that returns stored account data, allowing unauthenticated visitors to retrieve the connected service&amp;#39;s API secret and account details, which can then be used to disconnect the Privacy Policy Generator, Terms &amp; Conditions, GDPR, CCPA, Cookie Policy &amp; Disclaimer Templates WordPress plugin before 3.7.1&amp;#39;s integration.
Gravedad CVSS v3.1: MEDIA
Última modificación:
26/08/2026