Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2025-71335

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password. An attacker who already holds an active session, for example via a stolen session token or a device left logged in, remains authenticated as the legitimate user even after the user rotates their credentials, undermining the security purpose of the password change.
Gravedad CVSS v4.0: ALTA
Última modificación:
01/07/2026

CVE-2025-71334

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflowId and chatId parameters are UUIDs or numbers in file handling operations. By supplying a path-traversal value (e.g., '../../../../../tmp') as the chatflow id, an unauthenticated attacker can use the /api/v1/chatflows endpoint (via addBase64FilesToStorage) to write arbitrary files, and the /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints (via streamStorageFile) to read arbitrary files. Arbitrary file write may lead to remote code execution.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
01/07/2026

CVE-2025-71333

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary directories, potentially enabling remote code execution and server compromise.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
01/07/2026

CVE-2025-71340

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.ModifiedInterpreter.runcode in __reduce__ methods. Attackers can embed undetected code in pickle files that executes arbitrary commands when the file is loaded via pickle.load(), enabling supply chain attacks on PyTorch models and saved Python objects. This is fixed in version 0.0.30.
Gravedad CVSS v4.0: ALTA
Última modificación:
26/06/2026

CVE-2026-10098

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose serial is a prefix of the target serial to be reported as the revocation status of a different certificate. The lookup compared serial-number bytes without first requiring the two serial numbers to be of equal length, so a SingleResponse for one certificate (same issuer) whose serial is a prefix of the target's serial would match, returning the wrong certificate's status. The fix requires the serial lengths to be equal before comparing the serial bytes.
Gravedad CVSS v4.0: MEDIA
Última modificación:
27/06/2026

CVE-2025-71327

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts. Remote attackers can exploit this endpoint to register arbitrary accounts and authenticate to the system, gaining full API access without credentials.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
29/06/2026

CVE-2025-71328

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the account settings (Security) section without supplying the current password or any additional verification, as the application does not enforce a current-password check on the credential change. This can lead to full account takeover, particularly if an attacker can hijack or coerce an authenticated session.
Gravedad CVSS v4.0: ALTA
Última modificación:
29/06/2026

CVE-2025-71324

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints. The chatId value is not validated and is passed to streamStorageFile(), where a fallback file-lookup path constructed without the orgId is evaluated after the storage-directory containment check, allowing path traversal beyond the intended storage directory. Unauthenticated attackers can read sensitive files such as /root/.flowise/database.sqlite, exposing all database content in the default configuration.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/06/2026

CVE-2020-37256

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users with page editing capabilities can inject malicious scripts to execute arbitrary code and install malicious plugins for system access.
Gravedad CVSS v4.0: MEDIA
Última modificación:
27/06/2026

CVE-2021-47987

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an unreviewed personal fork of a contributor with write access. No releases were published with these tags; a project was exposed only if it defined a git-based dependency referencing one of the affected tags (for example, parse-server#4.9.3). The code behind the tags was not reviewed or approved, and although no malicious code was identified, the introduction of security vulnerabilities could not be ruled out.
Gravedad CVSS v4.0: ALTA
Última modificación:
26/06/2026

CVE-2021-47986

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attackers could exploit this by specifying affected version tags in dependency declarations to execute unreviewed and potentially malicious code.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/07/2026

CVE-2026-6678

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handling during decryption.
Gravedad CVSS v4.0: BAJA
Última modificación:
01/07/2026