Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-72711

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Lean 4 kernel does not check that the body of an opaque declaration is closed. environment::add_opaque omits the check_no_metavar_no_fvar call that the definition and theorem paths perform, so a value containing a free variable that is absent from the local context is not rejected outright. A metaprogram can first cause the kernel to create a temporary local of type False and record its type in the type checker's inference cache, then restore the local context while that cache entry persists on the same type checker instance, and finally submit an opaque declaration whose value is the now-unbound variable. The cache lookup answers before the branch that would test membership of the local context, so the kernel infers the cached type and admits an opaque constant of type False, from which any proposition follows. The declaration is accepted through the ordinary checked path at maximum kernel checking, without sorry, unsafeCast, debug.skipKernelTC, addDeclWithoutChecking, foreign code or a modified .olean file, and the result carries no axioms. Fixed in 4.32.2 by adding the missing closure check.
Gravedad CVSS v4.0: MEDIA
Última modificación:
24/08/2026

CVE-2026-71511

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticated attackers with member-read rights to retrieve bcrypt password verifiers by querying member endpoints. Attackers can call the individual member or member list endpoints to obtain crypted password verifier fields that are not filtered by the base API serializer or the Members API class, potentially enabling offline password cracking attacks.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/08/2026

CVE-2026-71510

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with user-read rights to extract sensitive data by splicing unsanitized filter parameters into SQL WHERE clauses without column restrictions. Attackers can perform binary search on numeric fields and LIKE prefix iteration on string fields to recover salary figures and password verifiers omitted from normal API responses, while raw database error messages in the same endpoint enable column name enumeration.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/08/2026

CVE-2026-63693

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Write
Gravedad CVSS v3.1: MEDIA
Última modificación:
24/08/2026

CVE-2026-61419

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
Gravedad CVSS v3.1: ALTA
Última modificación:
25/08/2026

CVE-2020-37268

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Print Assumptions does not report that a definition was produced while universe checking was disabled when that definition reaches the caller through Parameter Inline in a module type. Applying a functor inlines the body of the parameter, and the inlining drops the record that the term was built under Unset Universe Checking, so the resulting constant carries no trace of the unsafe operation. A module implementation can therefore prove False using a universe inconsistency, expose it through an inlined parameter, and have Print Assumptions report the dependent proof as closed under the global context. Because Print Assumptions is the in-process audit used to confirm that a development rests on no unexpected assumptions, a dependency built this way passes that audit while proving arbitrary propositions. The standalone checker coqchk does reject the resulting compiled file. The project records this in dev/doc/critical-bugs.md under non-fixed bugs and rates the risk as moderate when coqchk is not used.
Gravedad CVSS v4.0: MEDIA
Última modificación:
24/08/2026

CVE-2026-78417

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication.
Gravedad: Pendiente de análisis
Última modificación:
24/08/2026

CVE-2026-78541

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A stored OS<br /> command injection vulnerability exists in the parent-control module of TP-Link<br /> Archer BE3600 V1. An authenticated adjacent attacker with administrative access<br /> may store a crafted profile name containing shell metacharacters, which is<br /> later processed unsafely during daily cloud report generation and may result in<br /> arbitrary command execution.<br /> <br /> <br /> <br /> <br /> <br /> Successful<br /> exploitation may allow command execution on the affected device with potential<br /> impact to device confidentiality, integrity, and availability.
Gravedad CVSS v4.0: ALTA
Última modificación:
25/08/2026

CVE-2026-75370

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted CAN message.
Gravedad: Pendiente de análisis
Última modificación:
24/08/2026

CVE-2026-75371

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-proximate attackers with UART access to cause a Denial of Service (DoS) via a crafted input.
Gravedad: Pendiente de análisis
Última modificación:
24/08/2026

CVE-2026-71509

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint that allows authenticated attackers with expense-creation rights to bypass the approval workflow by directly setting approval status and approver identity fields. Attackers can manipulate workflow state fields through the REST API to advance expense reports to approved or closed status without possessing the dedicated approval right, while also creating forensic inconsistencies in audit records due to missing approval timestamps.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/08/2026

CVE-2026-71832

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial of Service
Gravedad: Pendiente de análisis
Última modificación:
24/08/2026