Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-40702

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
26/06/2026

CVE-2026-44622

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Gravedad CVSS v4.0: MEDIA
Última modificación:
26/06/2026

CVE-2026-50176

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.
Gravedad CVSS v4.0: ALTA
Última modificación:
26/06/2026

CVE-2026-22879

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability
Gravedad CVSS v3.1: ALTA
Última modificación:
26/06/2026

CVE-2026-12992

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature. When the VALIDITY rule is set to FULL, an attacker with Developer-role access can upload a WSDL document containing attacker-controlled import locations, causing the registry to issue HTTP requests to arbitrary internal URLs (server-side request forgery).
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-11800

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enables the attacker to impersonate any federated user linked to the affected Identity Provider, leading to unauthorized access and potential privilege escalation.
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-12975

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without enabling secure processing features or disabling external entity resolution. An attacker with artifact-write permission (or unauthenticated when the registry runs with default configuration) can upload a crafted XML document to trigger blind server-side request forgery (SSRF) via external DTD/entity fetch, or cause denial of service via entity expansion.
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-13282

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: High)
Gravedad CVSS v3.1: MEDIA
Última modificación:
26/06/2026

CVE-2026-11703

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for ticket-based resumption. A cached session could be resumed under a different SNI/ALPN than originally negotiated and, where client-authentication policy differs across virtual hosts, carry the cached peer-authentication state into a context it was not established for. Resumption now verifies the SNI/ALPN binding for all paths and declines (falling back to a full handshake) on mismatch.
Gravedad CVSS v4.0: MEDIA
Última modificación:
27/06/2026

CVE-2026-13281

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Gravedad CVSS v3.1: ALTA
Última modificación:
27/06/2026

CVE-2025-71338

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can exploit unsanitized fileName parameters with ../ sequences to overwrite critical files like package.json and achieve remote code execution when the application restarts.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
01/07/2026

CVE-2025-71336

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feature, which is designed to execute OS commands such as launching local MCP servers. Because Flowise's authentication and authorization model is minimal and lacks role-based access control, and the default installation runs without authentication unless FLOWISE_USERNAME and FLOWISE_PASSWORD are set, an attacker can send a crafted JSON payload with the header 'x-request-from: internal' to the /api/v1/node-load-method/customMCP endpoint to execute arbitrary OS commands, resulting in complete compromise of the platform container or server.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
01/07/2026