Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-69101

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration by supplying a crafted taskScript payload to the doEditWorkflow endpoint, which processes XML through an unhardened DocumentBuilderFactory with external entities and DTD loading enabled. Attackers can send a malicious XML document containing an external DTD reference to the edit_workflow action, causing the server to issue outbound HTTP requests to attacker-controlled infrastructure and exfiltrate local files readable by the TIS process user, including configuration files and Derby database credentials.
Gravedad CVSS v4.0: ALTA
Última modificación:
14/08/2026

CVE-2026-19879

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method performs a silent narrowing cast from 16-bit Unicode characters to 8-bit bytes when writing HTTP response header values. A remote attacker can exploit this by supplying specific Unicode characters in user-controlled input that an application places into response headers. This can lead to the truncation of these characters into ASCII control characters or special symbols, potentially resulting in limited integrity impact or information disclosure if the application does not properly sanitize user input.
Gravedad CVSS v3.1: MEDIA
Última modificación:
14/08/2026

CVE-2026-19880

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an <br /> MDC-based discriminator value flows unsanitized into a nested <br /> FileAppender path, letting an attacker who influences that MDC value <br /> (e.g. via an HTTP header)<br /> create and append log files outside the intended directory. <br /> <br /> <br /> This issue affects Logback-classic: from 0.9.14 through 1.6.2.
Gravedad CVSS v4.0: MEDIA
Última modificación:
14/08/2026

CVE-2026-58224

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in Samba&amp;#39;s CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets containing invalid field lengths, improperly terminated strings, or inconsistent packet sizes to be processed without adequate bounds checking. A remote attacker with access to the CTDB private network may trigger a denial of service through process crashes or excessive memory consumption and, in limited cases, disclose adjacent memory contents.
Gravedad CVSS v3.1: MEDIA
Última modificación:
14/08/2026

CVE-2026-53472

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in migration-planner. Insufficient validation of the `AgentStatusUpdate.CredentialUrl` field allows an authenticated attacker to store a malicious `javascript:` URL. When a victim views this URL in the Hybrid Cloud Console, it can lead to Cross-Site Scripting (XSS), enabling script execution in the victim&amp;#39;s session and potentially disclosing sensitive information.
Gravedad CVSS v3.1: MEDIA
Última modificación:
14/08/2026

CVE-2026-73633

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into memory without bounding how much it will accept, so a single request can exhaust the heap and deny service to other users. The plugin&amp;#39;s configurable JSON input length limit does not bound this read. The JSON plugin is an optional component; applications that do not use it, or use it without enabling JSON request-body handling, are not affected.<br /> <br /> This issue affects Apache Struts: from 2.1.8 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.10.0, from 7.0.0 through 7.2.1.<br /> <br /> Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
14/08/2026

CVE-2026-19871

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save controller falls back to the literal password "changeme" and the onboarding form provides no password field.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
14/08/2026

CVE-2026-1621

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality allows Exploitation of Trusted Identifiers.<br /> <br /> This issue affects E-Municipality: from 20251127 before 20260204.
Gravedad CVSS v3.1: MEDIA
Última modificación:
14/08/2026

CVE-2026-19828

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was identified in 648540858 wvp-GB28181-pro 2.7.4-20260107. This affects an unknown part of the file PlayController.java of the component Snapshot Endpoint. The manipulation of the argument deviceId/channelId leads to path traversal. The attack may be initiated remotely. The exploit is publicly available and might be used.
Gravedad CVSS v4.0: BAJA
Última modificación:
14/08/2026

CVE-2026-19827

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStream of the file /admin/controller/JobLogController.java of the component logDetailCat Endpoint. This manipulation of the argument executorAddress causes path traversal. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project closed the issue report as "not planned" without any further explanation.
Gravedad CVSS v4.0: MEDIA
Última modificación:
14/08/2026

CVE-2026-19768

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper control of generation of code (&amp;#39;Code Injection&amp;#39;) in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the settings configuration file.
Gravedad CVSS v3.1: ALTA
Última modificación:
14/08/2026

CVE-2026-73673

Fecha de publicación:
14/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a missing authentication enforcement flaw in the Boa web server and netis.cgi CGI dispatcher. Attackers can send a multipart POST request to /cgi-bin/upload_fw.cgi without a valid session cookie, bypassing authentication because Boa grants access to any path containing &amp;#39;.cgi&amp;#39; regardless of cookie validation, and netis.cgi reads but does not enforce the authentication state before invoking the firmware update handler, which accepts images validated only by a forgeable additive checksum and static product strings rather than a cryptographic signature, potentially enabling persistent router compromise.
Gravedad CVSS v4.0: ALTA
Última modificación:
14/08/2026