Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-21768

Fecha de publicación:
19/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/06/2026

CVE-2026-49358

Fecha de publicación:
19/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGenerator::$temporaryFiles` is a public array, and `removeTemporaryFiles()` — invoked from `__destruct()` and from a registered shutdown function — calls `unlink()` on every entry without verifying that the path is contained within the temporary folder. Any code holding a reference to a generator instance can push an arbitrary path into the array and have it deleted on script shutdown. This mirrors the KnpLabs/snappy issue GHSA-87qc-37cw-84h4. PhpWeasyPrint version 2.6.0 contains a patch for the issue.
Gravedad CVSS v3.1: BAJA
Última modificación:
23/06/2026

CVE-2026-52910

Fecha de publicación:
19/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> bpf: Free reuseport cBPF prog after RCU grace period.<br /> <br /> Eulgyu Kim reported the splat below with a repro. [0]<br /> <br /> The repro sets up a UDP reuseport group with a cBPF prog and<br /> replaces it with a new one while another thread is sending<br /> a UDP packet to the group.<br /> <br /> The reuseport prog is freed by sk_reuseport_prog_free().<br /> bpf_prog_put() is called for "e"BPF prog to destruct through<br /> multiple stages while cBPF prog is freed immediately by<br /> bpf_release_orig_filter() and bpf_prog_free().<br /> <br /> If a reuseport prog is detached from the setsockopt() path<br /> (reuseport_attach_prog() or reuseport_detach_prog()),<br /> sk_reuseport_prog_free() is called without waiting for RCU<br /> readers to complete, resulting in various bugs.<br /> <br /> Let&amp;#39;s defer freeing the reuseport cBPF prog after one RCU<br /> grace period.<br /> <br /> Note "e"BPF prog is safe as is unless the fast path starts<br /> to touch fields destroyed in bpf_prog_put_deferred() and<br /> __bpf_prog_put_noref().<br /> <br /> [0]:<br /> BUG: KASAN: vmalloc-out-of-bounds in reuseport_select_sock+0xedc/0x1220 net/core/sock_reuseport.c:596<br /> Read of size 4 at addr ffffc9000051e004 by task slowme/10208<br /> CPU: 6 UID: 1000 PID: 10208 Comm: slowme Not tainted 7.0.0-geb7ac95ff75e #32 PREEMPT(full)<br /> Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014<br /> Call Trace:<br /> <br /> dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120<br /> print_address_description mm/kasan/report.c:378 [inline]<br /> print_report+0xca/0x240 mm/kasan/report.c:482<br /> kasan_report+0x118/0x150 mm/kasan/report.c:595<br /> reuseport_select_sock+0xedc/0x1220 net/core/sock_reuseport.c:596<br /> udp4_lib_lookup2+0x3bc/0x950 net/ipv4/udp.c:495<br /> __udp4_lib_lookup+0x768/0xe20 net/ipv4/udp.c:723<br /> __udp4_lib_lookup_skb+0x297/0x390 net/ipv4/udp.c:752<br /> __udp4_lib_rcv+0x1312/0x2620 net/ipv4/udp.c:2752<br /> ip_protocol_deliver_rcu+0x282/0x440 net/ipv4/ip_input.c:207<br /> ip_local_deliver_finish+0x3bb/0x6f0 net/ipv4/ip_input.c:241<br /> NF_HOOK+0x30c/0x3a0 include/linux/netfilter.h:318<br /> NF_HOOK+0x30c/0x3a0 include/linux/netfilter.h:318<br /> __netif_receive_skb_one_core net/core/dev.c:6181 [inline]<br /> __netif_receive_skb net/core/dev.c:6294 [inline]<br /> process_backlog+0xaa4/0x1960 net/core/dev.c:6645<br /> __napi_poll+0xae/0x340 net/core/dev.c:7709<br /> napi_poll net/core/dev.c:7772 [inline]<br /> net_rx_action+0x5d7/0xf50 net/core/dev.c:7929<br /> handle_softirqs+0x22b/0x870 kernel/softirq.c:622<br /> do_softirq+0x76/0xd0 kernel/softirq.c:523<br /> <br /> <br /> __local_bh_enable_ip+0xf8/0x130 kernel/softirq.c:450<br /> local_bh_enable include/linux/bottom_half.h:33 [inline]<br /> rcu_read_unlock_bh include/linux/rcupdate.h:924 [inline]<br /> __dev_queue_xmit+0x1dd7/0x3710 net/core/dev.c:4890<br /> neigh_output include/net/neighbour.h:556 [inline]<br /> ip_finish_output2+0xca9/0x1070 net/ipv4/ip_output.c:237<br /> NF_HOOK_COND include/linux/netfilter.h:307 [inline]<br /> ip_output+0x29f/0x450 net/ipv4/ip_output.c:438<br /> ip_send_skb+0x45/0xc0 net/ipv4/ip_output.c:1508<br /> udp_send_skb+0xb04/0x1510 net/ipv4/udp.c:1195<br /> udp_sendmsg+0x1a71/0x2350 net/ipv4/udp.c:1485<br /> sock_sendmsg_nosec net/socket.c:727 [inline]<br /> __sock_sendmsg net/socket.c:742 [inline]<br /> __sys_sendto+0x554/0x680 net/socket.c:2206<br /> __do_sys_sendto net/socket.c:2213 [inline]<br /> __se_sys_sendto net/socket.c:2209 [inline]<br /> __x64_sys_sendto+0xde/0x100 net/socket.c:2209<br /> do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]<br /> do_syscall_64+0x160/0xf80 arch/x86/entry/syscall_64.c:94<br /> entry_SYSCALL_64_after_hwframe+0x77/0x7f<br /> RIP: 0033:0x415a2d<br /> Code: b3 66 2e 0f 1f 84 00 00 00 00 00 66 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48<br /> RSP: 002b:00007f6bc31e41e8 EFLAGS: 00000212 ORIG_RAX: 000000000000002c<br /> RAX: ffffffffffffffda RBX: 00007f6bc31e4cdc RCX: 0000000000415a2d<br /> RDX: 0000000000000001 RSI: 00007f6bc31e421f RDI: 0000000000000003<br /> RBP: 00007f6bc31e4240 R08: 00007f6bc31e4220 R09: 0000000000000010<br /> R10: 0000000000000000 R11: <br /> ---truncated---
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-52909

Fecha de publicación:
19/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ip6_vti: set netns_immutable on the fallback device.<br /> <br /> john1988 and Noam Rathaus reported that vti6_init_net() does not set the<br /> netns_immutable flag on the per-netns fallback tunnel device (ip6_vti0).<br /> <br /> Other similar tunnel drivers (like ip6_tunnel, sit, ip6_gre, and ip_tunnel)<br /> correctly set this flag during their fallback device initialization to<br /> prevent them from being moved to another network namespace.
Gravedad CVSS v3.1: ALTA
Última modificación:
08/07/2026

CVE-2026-52908

Fecha de publicación:
19/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> RDMA: During rereg_mr ensure that REREG_ACCESS is compatible<br /> <br /> If IB_MR_REREG_ACCESS changes from RO to RW then the umem has to be<br /> re-evaluated to ensure it is properly pinned as RW. Since the umem is<br /> hidden inside each driver&amp;#39;s mr struct add a ib_umem_check_rereg() function<br /> that each driver has to call before processing IB_MR_REREG_ACCESS.<br /> <br /> mlx4 has to retain its duplicate ib_access_writable check because it<br /> implements IB_MR_REREG_ACCESS | IB_MR_REREG_TRANS by changing both items<br /> in place sequentially while the MR is live, so it will continue to not<br /> support this combination.
Gravedad CVSS v3.1: ALTA
Última modificación:
08/07/2026

CVE-2022-50971

Fecha de publicación:
19/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Malwarebytes 4.5 contains an unquoted service path vulnerability in the MBAMService executable that allows local attackers to escalate privileges by injecting malicious code into the system root path. Attackers can place executable files in unquoted path directories that execute with LocalSystem privileges during service startup or system reboot.
Gravedad CVSS v4.0: ALTA
Última modificación:
26/06/2026

CVE-2020-37252

Fecha de publicación:
19/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Realtek Audio Service 1.0.0.55 contains an unquoted service path vulnerability in RtkAudioService64.exe that allows local attackers to escalate privileges by injecting malicious code. Attackers can place executable files in the unquoted service path directory to execute arbitrary code with LocalSystem privileges during service startup or system reboot.
Gravedad CVSS v4.0: ALTA
Última modificación:
23/06/2026

CVE-2025-71326

Fecha de publicación:
19/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** AVAST Antivirus 25.11 contains an unquoted service path vulnerability in the SecureLine service that allows local non-privileged users to execute code with elevated SYSTEM privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that execute with high-level system permissions.
Gravedad CVSS v4.0: ALTA
Última modificación:
23/06/2026

CVE-2020-37253

Fecha de publicación:
19/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Winstep 18.06.0096 contains an unquoted service path vulnerability in the Winstep Xtreme Service that allows local attackers to escalate privileges. Attackers can place malicious executables in the Program Files directory to be executed with LocalSystem privileges when the service starts.
Gravedad CVSS v4.0: ALTA
Última modificación:
23/06/2026

CVE-2021-47985

Fecha de publicación:
19/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Brother SAPSprint 7.60 contains an unquoted service path vulnerability in the SAPSprint service binary that allows local attackers to escalate privileges. Attackers can place a malicious executable in the Program Files directory path to be executed with LocalSystem privileges when the service starts automatically.
Gravedad CVSS v4.0: ALTA
Última modificación:
23/06/2026

CVE-2023-54353

Fecha de publicación:
19/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the PsyFrameGrabberService that allows local attackers to execute arbitrary code by placing malicious executables in unquoted path directories. Attackers with write access to C:\ or subdirectories like C:\Program Files (x86)\Personify\ can place a malicious Program.exe or PsyFrameGrabberService.exe file that executes with LocalSystem privileges when the service starts automatically at boot.
Gravedad CVSS v4.0: ALTA
Última modificación:
23/06/2026

CVE-2020-37254

Fecha de publicación:
19/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Wondershare PDFelement 5.2.9 contains a privilege escalation vulnerability due to an unquoted service path in the WsAppService Windows service. Local attackers can place a malicious executable in the service path and execute code with LocalSystem privileges upon service restart or system reboot.
Gravedad CVSS v4.0: ALTA
Última modificación:
23/06/2026