Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-57951

Fecha de publicación:
29/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Mythic before 3.4.0.60 contains a broken hasura permission filter on the payload_build_step table with an always-satisfied _or condition that bypasses operation-scoped access controls. Authenticated operators and spectators can query payload_build_step to read step_stdout, step_stderr, step_name, and step_description across all operations on the server.
Gravedad CVSS v4.0: ALTA
Última modificación:
14/07/2026

CVE-2026-57952

Fecha de publicación:
29/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile_config_check_webhook, c2profile_redirect_rules_webhook, c2profile_get_ioc_webhook, c2profile_sample_message_webhook) that fail to verify payload ownership. An operator in one operation can invoke these endpoints with a known payload UUID from another operation to access that operation's C2 profile configuration including encryption keys and callback parameters.
Gravedad CVSS v4.0: MEDIA
Última modificación:
14/07/2026

CVE-2026-57953

Fecha de publicación:
29/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Mythic before 3.4.0.60 contains an authorization bypass vulnerability that allows authenticated spectator-role users to perform unauthorized write operations by accessing the eventing_import_automatic_webhook endpoint registered under spectator-permitted middleware. Attackers with spectator role can exploit this misconfigured access control to create and delete automation workflows, making unauthorized modifications to operation automation configuration and EventGroups.
Gravedad CVSS v4.0: MEDIA
Última modificación:
14/07/2026

CVE-2026-57955

Fecha de publicación:
29/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary ClickHouse queries by injecting URL-encoded quotes into the rule ID path parameter of the alert-history endpoints. Attackers can manipulate the unsanitized rule ID interpolated into ClickHouse queries to read all stored traces, logs, and metrics, or abuse the url() function to perform server-side request forgery.
Gravedad CVSS v4.0: ALTA
Última modificación:
14/07/2026

CVE-2026-57954

Fecha de publicación:
29/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSortingRules, allowing attackers to sort collections by forbidden fields. Attackers can infer hidden field values through row ordering analysis, leaking relative field ordering across all rows via both JSON:API and GraphQL read paths.
Gravedad CVSS v4.0: MEDIA
Última modificación:
30/06/2026

CVE-2026-57943

Fecha de publicación:
29/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** LibrePhotos before 1.0.0 contains a broken object level authorization vulnerability in the SetPhotosShared endpoint that allows authenticated users to grant themselves access to other users' private photos by bypassing ownership validation. Attackers can manipulate shared_to relations without proper owner checks to read arbitrary private photos belonging to other users.
Gravedad CVSS v4.0: MEDIA
Última modificación:
14/07/2026

CVE-2026-57945

Fecha de publicación:
29/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** PhotoPrism before 260601-a7d098548 contains a broken access control vulnerability that allows authenticated non-admin users to modify other users' profile information by sending requests to arbitrary user endpoints. Attackers can exploit the missing session-to-user identifier validation in the PUT users API endpoint to overwrite another user's profile details without authorization.
Gravedad CVSS v4.0: MEDIA
Última modificación:
14/07/2026

CVE-2026-57946

Fecha de publicación:
29/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist endpoint without authentication. Attackers can supply a playlist ID to the feed endpoint to obtain the full playlist contents, owner email address, and associated video entries without any authentication.
Gravedad CVSS v4.0: MEDIA
Última modificación:
14/07/2026

CVE-2026-57947

Fecha de publicación:
29/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that allows authenticated users to register internal URLs due to missing SSRF protection. Attackers can trigger alarm threshold breaches to force the server to issue POST requests to internal hosts and metadata endpoints, enabling unauthorized access to internal network resources.
Gravedad CVSS v4.0: MEDIA
Última modificación:
14/07/2026

CVE-2026-57948

Fecha de publicación:
29/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript access via document.cookie and cleartext transmission over HTTP. Attackers can exploit stored or reflected cross-site scripting vulnerabilities to exfiltrate the session token or intercept it through network sniffing to perform session hijacking.
Gravedad CVSS v4.0: ALTA
Última modificación:
14/07/2026

CVE-2026-57949

Fecha de publicación:
29/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that allows authenticated users to read any follow-up record by iterating sequential numeric IDs. Attackers can exploit this by sending requests with arbitrary ID parameters to access other users' follow-up notes, file attachments, scheduling information, and business entity references without proper authorization checks.
Gravedad CVSS v4.0: ALTA
Última modificación:
14/07/2026

CVE-2026-57942

Fecha de publicación:
29/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** LibreTranslate through 1.9.7, fixed in commit 397fd22, contains an IP spoofing vulnerability in the get_remote_address() function that allows unauthenticated attackers to spoof client IP addresses by injecting arbitrary values into the X-Forwarded-For header without trusted proxy validation. Attackers can bypass per-IP rate limiting and flood bans by supplying forged addresses in the X-Forwarded-For header to enable unlimited API abuse.
Gravedad CVSS v4.0: MEDIA
Última modificación:
29/06/2026