Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-18938

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2026-49008

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to the integrity verification of a specific application function on the device.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2026-49006

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmission.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2026-49007

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface.
Gravedad CVSS v3.1: ALTA
Última modificación:
07/08/2026

CVE-2026-16027

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye&amp;#39;s E-Signature allows Server Side Request Forgery.<br /> <br /> This issue affects Türkiye&amp;#39;s E-Signature: from 2.4.4.0 before 2.5.1.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2026-19079

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find and chcon commands to locate and relabel unlabeled files under /tmp and other directories. A local attacker could exploit a race window between the file discovery and the label change operation by swapping directory components with symlinks, causing chcon to follow the symlink and modify SELinux labels on arbitrary system files. This could undermine SELinux mandatory access control protections on critical files such as /etc/shadow.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2026-15148

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site&amp;#39;s configured merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to mark any booking as paid without a legitimate payment reaching the merchant, including other users&amp;#39; bookings.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2026-15211

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal order token to the order being completed on the WooCommerce order-received flow: it captures a client-supplied token and marks the order paid whenever the capture status is COMPLETED, without comparing the captured amount to the order total. This allows an attacker (unauthenticated where guest checkout is enabled) to substitute an approved, uncaptured PayPal order token and have an expensive order marked paid without paying its price.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2026-15239

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator integration, instead keying it to an attacker-controlled, reusable request value, allowing unauthenticated attackers to solve one challenge and then replay token-less form submissions for a short window, defeating the anti-abuse protection the plugin provides.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2026-12261

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability in `nltk.downloader` in nltk/nltk versions
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/08/2026

CVE-2026-16039

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller&amp;#39;s own orders, allowing any authenticated user, including Subscribers, to read every WooCommerce order in the store together with each customer&amp;#39;s personal information.
Gravedad: Pendiente de análisis
Última modificación:
07/08/2026

CVE-2026-16041

Fecha de publicación:
07/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept reviews only from verified owners.
Gravedad: Pendiente de análisis
Última modificación:
07/08/2026