Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-34497

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS).<br /> <br /> This issue affects FM Systems Employee: before 2025.3.1.
Gravedad CVSS v4.0: MEDIA
Última modificación:
31/07/2026

CVE-2026-21662

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files.<br /> <br /> This issue affects FM Systems Employee: before 2025.3.1.
Gravedad CVSS v4.0: MEDIA
Última modificación:
31/07/2026

CVE-2026-67822

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled &amp;#39;GO&amp;#39; and &amp;#39;index&amp;#39; parameters into a 64-byte stack buffer without length restriction, leading to stack overflow.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
31/07/2026

CVE-2026-58047

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HTTP Smuggling in cPanel allows potential leak of credentials.
Gravedad CVSS v4.0: MEDIA
Última modificación:
31/07/2026

CVE-2026-58048

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
31/07/2026

CVE-2026-54707

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files setting in cli/onionshare_cli/web/receive_mode.py, where ReceiveModeRequest._get_file_stream() writes multipart file[] data to disk despite the text-only setting. This issue is fixed in version 2.6.4.
Gravedad CVSS v3.1: MEDIA
Última modificación:
31/07/2026

CVE-2026-52856

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.
Gravedad CVSS v3.1: ALTA
Última modificación:
31/07/2026

CVE-2026-54706

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/send_base_mode.py through SendBaseModeWeb.set_file_info() and stream_individual_file(), allowing remote recipients of Share or Website mode to read local files outside the selected directory. This issue is fixed in version 2.6.4.
Gravedad CVSS v3.1: MEDIA
Última modificación:
31/07/2026

CVE-2026-52855

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token_id}}, and {{config.docker.registries}} from the full daemon configuration. This issue is fixed in version 1.12.3.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
31/07/2026

CVE-2026-67607

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** LightFTP 2.3.1 contains a race condition vulnerability that allows remote attackers to crash the server by racing a fresh connection that reuses the FTP context against an in-progress ABRT cleanup. Attackers can exploit the unprotected re-check of WorkerThreadId between worker_thread_cleanup() and pthread_join() outside of MTLock to cause pthread_join() to operate on an invalid thread ID, resulting in a server crash. CVE-2024-11144 identifies an incomplete fix of this vulnerability.
Gravedad CVSS v4.0: ALTA
Última modificación:
31/07/2026

CVE-2026-59231

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server to arbitrary attacker-chosen destinations via unvalidated URLs stored in the finding images field or the report client_logo field, which the server-side headless browser fetches while rendering the report.
Gravedad CVSS v4.0: MEDIA
Última modificación:
31/07/2026

CVE-2026-59232

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the create or update lead permission to execute arbitrary JavaScript in the application origin via HTML markup stored in the lead name field, which the view renders through Blade&amp;#39;s unescaped output directive and inside a JavaScript string literal in an onclick attribute.
Gravedad CVSS v4.0: MEDIA
Última modificación:
31/07/2026