Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-54742

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Lemmy is a link aggregator and forum for the fediverse. From 0.19.18 until 0.19.19 and 1.0.0-alpha.20, a community moderator can feature or unfeature posts in other communities through federated CollectionAdd and CollectionRemove activities using CollectionType::Featured. After verify_mod_action authorizes the actor against self.community(), the receive handlers in crates/apub/activities/src/community/collection_add.rs and crates/apub/activities/src/community/collection_remove.rs dereference self.object as an ApubPost and update featured_community without verifying that post.community_id equals community.id. A moderator can therefore target an unrelated post owned by another community, push it into featured feeds and listings, or undo another community's legitimate curation decision. This issue is fixed in versions 0.19.19 and 1.0.0-alpha.20.
Gravedad CVSS v4.0: MEDIA
Última modificación:
19/08/2026

CVE-2026-55085

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates the start attribute of a numbered list directly into an unquoted ol start attribute before assigning the generated markup to node.innerHTML. ImportEtherpad.setPadRaw in src/node/utils/ImportEtherpad.ts accepts attacker-controlled attribute-pool values from a crafted .etherpad import, including list:number1 and a malicious start value. Any user with write access to a pad can store markup that executes as cross-site scripting when another user opens the pad or /timeslider, including when an administrator views the pad. This issue is fixed in version 3.3.1.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
19/08/2026

CVE-2026-55086

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and src/node/handler/ExportHandler.ts derive temporary filenames from Math.random() and place them in os.tmpdir(). On a host with a shared world-writable temporary directory, a local unprivileged attacker who predicts a filename can precreate a symbolic link to a file writable by the Etherpad process. Subsequent import or export operations can follow the link through fs.writeFile, fs.rename, or document-conversion output and overwrite the target with partially attacker-controlled content. This issue is fixed in version 3.1.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
19/08/2026

CVE-2026-55087

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-controlled x-proxy-path request header in src/node/hooks/express/admin.ts when substituting paths into HTML, JavaScript, and CSS under /admin without sanitization, Vary: x-proxy-path, or Cache-Control: private, no-store. A shared proxy or CDN can cache the resulting response and serve attacker-injected script to an administrator. In src/node/hooks/express/specialpages.ts, version 3.0.0 also accepts a protocol-relative x-proxy-path value when constructing the /p/:pad/timeslider redirect, allowing redirection to an attacker-controlled host. The issues are exploitable when the deployment permits client-supplied x-proxy-path headers to reach Etherpad. This issue is fixed in version 3.1.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
19/08/2026

CVE-2026-55088

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/express/tokenTransfer.ts uses POST /tokenTransfer to store an author token for transfer between browsers and exposes it through GET /tokenTransfer/{uuid}. Although the record includes createdAt, the transfer has no expiration check, is not removed after successful redemption, and is returned by res.send(tokenData), including the raw author token. An unauthenticated attacker who obtains a transfer UUID can repeatedly redeem it, receive fresh author cookies, read the cleartext token, and impersonate the originating author for pad read and write operations. This issue is fixed in version 3.1.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
19/08/2026

CVE-2026-22306

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext <br /> transmission of sensitive information vulnerability in Ozols Grupa OZOLS<br /> on Windows caused by an abandoned auto-update domain. Affected<br /> component: the automatic update channel - OzolsSQL client update path, the _update SQL Server Agent job (@subsystem = N&amp;#39;ActiveScripting&amp;#39;) and serv_update.vbs.<br /> <br /> This issue affects OZOLS: before 1.1.1233.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
19/08/2026

CVE-2026-19505

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper cryptographic signature verification in `jst_functions.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to bypass authentication and obtain administrative access via a forged JWT containing an invalid RSA signature.
Gravedad: Pendiente de análisis
Última modificación:
19/08/2026

CVE-2026-19506

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Race condition in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to gain unauthorized access via concurrent authentication requests that exploit shared authentication state.
Gravedad: Pendiente de análisis
Última modificación:
19/08/2026

CVE-2026-19507

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Uncontrolled resource consumption in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause denial of service via excessively large password values.
Gravedad: Pendiente de análisis
Última modificación:
19/08/2026

CVE-2026-19508

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Heap-based buffer overflow in the multipart form-data parser in `jst_post.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause memory corruption and denial of service, and potentially execute arbitrary code, via a crafted multipart/form-data request.
Gravedad: Pendiente de análisis
Última modificación:
19/08/2026

CVE-2026-19509

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper input validation in `ajaxSet_wireless_network_configuration.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows an authenticated attacker to cause denial of service via a crafted `ssid_number` parameter.
Gravedad: Pendiente de análisis
Última modificación:
19/08/2026

CVE-2026-17590

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-32475. Reason: This candidate is a reservation duplicate of CVE-2026-32475. Notes: All CVE users should reference CVE-2026-32475 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
Gravedad: Pendiente de análisis
Última modificación:
19/08/2026