Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-6731

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN violates an issuing CA's DNS name constraints could be accepted.
Gravedad CVSS v4.0: MEDIA
Última modificación:
27/06/2026

CVE-2026-6681

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.
Gravedad CVSS v4.0: BAJA
Última modificación:
27/06/2026

CVE-2026-6679

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. The buffer overflow was due to an integer truncation when computing the length of the ACK record-number list, causing an undersized buffer to be allocated and then overrun. This affects builds using DTLS 1.3 and wolfSSL version 5.9.0 and earlier. A fix was added to the 5.9.1 release.
Gravedad CVSS v4.0: ALTA
Última modificación:
27/06/2026

CVE-2026-6450

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allowing a crafted CRL with an unhandled critical extension to be accepted. This only affects builds with CRL support enabled and where a crafted CRL had a trusted signature when parsed.
Gravedad CVSS v4.0: BAJA
Última modificación:
27/06/2026

CVE-2026-6412

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5 in certificate processing.
Gravedad CVSS v4.0: BAJA
Última modificación:
27/06/2026

CVE-2026-56445

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths.
Gravedad CVSS v4.0: ALTA
Última modificación:
26/06/2026

CVE-2026-38640

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted string.
Gravedad CVSS v3.1: ALTA
Última modificación:
26/06/2026

CVE-2026-12473

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global authentication service in OHIF automatically injects the authenticated user's OIDC Bearer token into the resulting requests, sending it to the attacker-controlled server. DICOMweb data sources are not impacted.
Gravedad CVSS v4.0: ALTA
Última modificación:
26/06/2026

CVE-2026-37452

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSIAPService.exe component
Gravedad CVSS v3.1: ALTA
Última modificación:
26/06/2026

CVE-2026-38637

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.
Gravedad CVSS v3.1: ALTA
Última modificación:
26/06/2026

CVE-2026-57520

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an organization by exploiting a missing role hierarchy check in the bulk user-remove endpoint. Attackers can supply Admin organization-user IDs in a bulk DELETE request to bypass the guard enforced on the single-user removal path, effectively removing one or more Admin accounts from an organization.
Gravedad CVSS v4.0: ALTA
Última modificación:
14/07/2026

CVE-2026-57521

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access arbitrary organization billing data by supplying an arbitrary organizationId to the PreviewInvoiceController endpoints without membership or authorization checks. Attackers can exploit the missing ManageOrganizationBillingRequirement on the preview invoice endpoints to retrieve Stripe-computed tax totals, subscription status, and billing details derived from any target organization's real customer and subscription data.
Gravedad CVSS v4.0: MEDIA
Última modificación:
14/07/2026