Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-10845

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/06/2026

CVE-2026-11372

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Gravedad CVSS v3.1: MEDIA
Última modificación:
30/06/2026

CVE-2024-51454

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 through 7.1 Interim Fix 004 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
Gravedad CVSS v3.1: MEDIA
Última modificación:
26/06/2026

CVE-2023-33854

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow an authenticated user to bypass client-side validation and manipulate input data using man in the middle techniques.
Gravedad CVSS v3.1: MEDIA
Última modificación:
30/06/2026

CVE-2026-9162

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Mattermost versions 11.7.x
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/06/2026

CVE-2026-9029

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).
Gravedad CVSS v3.1: ALTA
Última modificación:
10/07/2026

CVE-2026-8074

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Mattermost versions 11.7.x
Gravedad CVSS v3.1: BAJA
Última modificación:
23/06/2026

CVE-2026-7165

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** The vulnerability is present in the ‘/addJugador’ endpoint:<br /> * The &amp;#39;keyJugador&amp;#39; and &amp;#39;keyJugadorObjectiu&amp;#39; parameters allow the modification of other users’ information without requiring prior authorization validation. This could enable an authenticated attacker to alter any user’s ID and change their information.<br /> <br /> * The ‘punts’ and ‘numObjectiusEliminats’ fields allow arbitrary data to be added because user input is not properly validated. This makes it possible to obtain authentic prizes, awarded by city councils, by falsifying game scores. <br /> <br /> * In the ‘tokens’ field, administrative privileges can be self-assigned without server validation or prior authentication. This vulnerability could allow an authenticated attacker to grant themselves administrator permissions and thus escalate privileges.<br /> <br /> * Numeric fields allow the entry of extremely long values, which can cause the system to crash. Successful exploitation of this vulnerability could allow an authenticated attacker to launch a denial-of-service (DoS) attack, preventing created games from being playable.<br /> <br /> * The ‘urlImatge’ parameter allows server-side requests to arbitrary URLs, enabling the retrieval of users’ internal IP addresses, access to internal services, reading of local files, and unauthorized interaction with third-party APIs. An authenticated attacker could gain access to sensitive data.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
22/06/2026

CVE-2026-7166

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and phone number data from the ‘email’ and ‘telefon’ fields. This vulnerability is also present in the local database, as it contains accessible sensitive information such as data on minors and municipal users. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to gain access to sensitive information and data.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
22/06/2026

CVE-2026-7167

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** The vulnerability arises when the system fails to properly validate the &amp;#39;email&amp;#39; field during the authentication process, allowing unverified or fake email addresses to be accepted. This lack of validation enables the creation of user accounts with fake email addresses, facilitating the mass creation of fraudulent accounts. Successful exploitation of this vulnerability could allow an authenticated attacker to carry out various attacks, such as mass spam distribution, system abuse, or bypassing user controls, thereby compromising the security and integrity of the system.
Gravedad CVSS v4.0: MEDIA
Última modificación:
22/06/2026

CVE-2026-6673

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Mattermost versions 11.7.x
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/06/2026

CVE-2026-6062

Fecha de publicación:
22/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Mattermost versions 11.7.x
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/06/2026