Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-72799

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** SiYuan before v3.7.4 (affected
Gravedad CVSS v4.0: MEDIA
Última modificación:
12/08/2026

CVE-2026-72800

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint, allowing authenticated readers to retrieve complete database column schemas including descriptions, select vocabularies, and template expressions. Additionally, getBlockDefIDsByRefText and getBlockRelevantIDs endpoints enumerate workspace-wide block IDs without publish scoping, enabling attackers to discover valid block identifiers across publish boundaries and access content from hidden or password-protected documents.
Gravedad CVSS v4.0: MEDIA
Última modificación:
12/08/2026

CVE-2026-72801

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish mode. Attackers can retrieve Argon2id salt, cost parameters, password verifiers, and wrapped notebook keys to perform unlimited offline master-password cracking without rate limiting.
Gravedad CVSS v4.0: ALTA
Última modificación:
12/08/2026

CVE-2026-72788

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fails to properly restrict administrator workspace state from publish readers. Unauthenticated attackers can retrieve the administrator's open documents, search terms, notebook paths, and private asset locations by calling the getConf endpoint without authentication.
Gravedad CVSS v4.0: MEDIA
Última modificación:
12/08/2026

CVE-2026-72789

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypted notebooks through the publish API without authentication or key material.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
12/08/2026

CVE-2026-72790

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint that returns notebook metadata without authorization checks. Attackers can read notebook names, document counts, sizes, and timestamps for closed or non-published notebooks that should be hidden from readers.
Gravedad CVSS v4.0: MEDIA
Última modificación:
12/08/2026

CVE-2026-72792

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that returns tag labels and occurrence counts from password-protected documents to unauthenticated readers. Attackers can enumerate tag vocabulary and internal terminology from password-protected documents by calling the tag endpoint without providing the document's publish password.
Gravedad CVSS v4.0: MEDIA
Última modificación:
12/08/2026

CVE-2026-72793

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader users to obtain the session-cookie signing key, OS username via pandoc path, and encrypted-notebook key material. Attackers can forge and tamper with session cookies to impersonate users, and on instances without access-auth codes configured, escalate to administrator privileges.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
12/08/2026

CVE-2026-72794

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthenticated users in publish mode. Attackers can retrieve the CookieKey value and forge valid session cookies to impersonate users or gain administrative access.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
12/08/2026

CVE-2026-6821

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to bypass IP-based access restrictions and read limited merge request information from a private project due to missing authorization checks in a merge requests API endpoint.
Gravedad CVSS v3.1: MEDIA
Última modificación:
12/08/2026

CVE-2026-72508

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly privileged ServiceAccount (SA). This enables the tenant to deploy arbitrary cluster-scoped resources, leading to privilege escalation and potential arbitrary code execution across the cluster.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
12/08/2026

CVE-2026-72786

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change passwords without verification. Attackers with edit users permission can reset any user's password including administrators by exploiting the unprotected newPassword field in the User element save flow.
Gravedad CVSS v4.0: ALTA
Última modificación:
12/08/2026