Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-11779

Fecha de publicación:
26/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.
Gravedad CVSS v4.0: MEDIA
Última modificación:
26/06/2026

CVE-2025-32423

Fecha de publicación:
26/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is a DoS vulnerability in ExtractTextInformationBlock. Malicious users can amplify their input. For example, if a malicious user inputs 10K of content, the server will consume 50G of memory, eventually causing memory resources to be exhausted, resulting in DoS. This vulnerability is fixed in 0.6.32.
Gravedad CVSS v4.0: MEDIA
Última modificación:
29/06/2026

CVE-2025-32394

Fecha de publicación:
26/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is a DoS vulnerability in AITextSummarizerBlock. Malicious users can amplify their input. For example, if a malicious user inputs 10K of content, the server will consume 50G of memory, eventually causing memory resources to be exhausted, resulting in DoS. This vulnerability is fixed in 0.6.32.
Gravedad CVSS v4.0: MEDIA
Última modificación:
27/06/2026

CVE-2026-9640

Fecha de publicación:
26/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.. An authenticated project operator in a restricted multi-tenant environment can bypass policy restrictions by importing a maliciously crafted instance backup containing restricted configuration keys within a snapshot. When the snapshot is restored, these restricted keys are applied to the live instance without policy validation. Starting the modified instance grants the operator unauthorized host root access.
Gravedad CVSS v3.1: ALTA
Última modificación:
02/07/2026

CVE-2026-9639

Fecha de publicación:
26/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field.
Gravedad CVSS v3.1: MEDIA
Última modificación:
02/07/2026

CVE-2026-5757

Fecha de publicación:
26/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy persistence.
Gravedad CVSS v3.1: ALTA
Última modificación:
29/06/2026

CVE-2026-47214

Fecha de publicación:
26/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the HTML backend has unsafe URI and path handling. This vulnerability is fixed in 2.94.0.
Gravedad CVSS v3.1: ALTA
Última modificación:
02/07/2026

CVE-2026-45195

Fecha de publicación:
26/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory read or write outside the permitted range of memory for the host kernel.<br /> <br /> <br /> <br /> Addresses passed to the GPU Firmware can be used by the Firmware for more privileged memory accesses than are permitted by the system.
Gravedad CVSS v3.1: ALTA
Última modificación:
29/06/2026

CVE-2026-21734

Fecha de publicación:
26/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits on the device.<br /> <br /> <br /> <br /> An edge case using a very small value in GPU shader code can cause a segmentation fault in the GPU shader compiler due to am out-of-bounds write.
Gravedad CVSS v3.1: ALTA
Última modificación:
29/06/2026

CVE-2026-12411

Fecha de publicación:
26/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest&amp;#39;s custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled.
Gravedad CVSS v3.1: ALTA
Última modificación:
02/07/2026

CVE-2026-44018

Fecha de publicación:
26/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend&amp;#39;s XML parsing and the input document format detection lacked security controls. An attacker could craft malicious METS-GBS archives that, when processed, could read sensitive files, exhaust system resources, or cause application crashes. This vulnerability is fixed in 2.91.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/06/2026

CVE-2025-11919

Fecha de publicación:
26/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** The default JVM can access files and directories under `/tmp/` including the `$TemporaryDirectory` of other users on the same cloud instance (`/tmp/UserTemporaryFiles/`). The `-init` file for the the JVM initialization exists in the vulnerable directory during the startup of the JVM. An attacker with access to the shared `/tmp/` space can preemptively create or replace `.jar` files or directories (via the `-init` file) that the victim JVM will resolve first in its classpath. By strategically placing a malicious version of a commonly used library (e.g., `commons-io`) in a location that is included in the classpath before the legitimate version, an attacker can cause the JVM to load the malicious class during startup, thereby executing the attacker&amp;#39;s code.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
26/06/2026