Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2025-53831

Fecha de publicación:
06/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** DrawIO for ownCloud is an application for using DrawIO with the file storage, synchronization, and sharing application ownCloud Classic. In DrawIO for ownCloud prior to version 1.0.2, which corresponds to ownCloud 10 prior to version 10.15.3, attackers with access to the DrawIO app can leverage improper neutralization of input during web page generation to achieve stored XSS. Upgrade ownCloud 10 to version 10.15.3 or later or upgrade DrawIO for ownCloud 10 to version 1.0.2 or later to receive a patch.
Gravedad CVSS v3.1: ALTA
Última modificación:
06/07/2026

CVE-2026-5268

Fecha de publicación:
06/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An authentication bypass vulnerability exists in<br /> the default SFTP server component utilized across the Ciena products listed. This vulnerability allows a remote, unauthenticated attacker to bypass<br /> security controls and gain unauthorized access to the underlying filesystem.<br /> Successful exploitation could allow an attacker to read or modify system files.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
08/07/2026

CVE-2026-59194

Fecha de publicación:
06/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patches directory and cause pnpm patch-remove to delete an arbitrary reachable file. This vulnerability is fixed in 10.34.4 and 11.7.0.
Gravedad CVSS v3.1: ALTA
Última modificación:
07/07/2026

CVE-2026-59196

Fecha de publicación:
06/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted node_modules directory. Traversal aliases could escape that directory, while reserved aliases such as .bin or .pnpm could overwrite pnpm-owned layout. This vulnerability is fixed in 10.34.4 and 11.7.0.
Gravedad CVSS v3.1: ALTA
Última modificación:
07/07/2026

CVE-2026-59195

Fecha de publicación:
06/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependencies section and uses those names directly when creating config dependency symlinks under node_modules/.pnpm-config. A malicious repository can commit a crafted pnpm-lock.yaml whose env-lockfile document contains a traversal-shaped config dependency name. During pnpm install, pnpm installs the config dependency and creates a symlink at a path derived from that name. This vulnerability is fixed in 10.34.4 and 11.8.0.
Gravedad CVSS v3.1: ALTA
Última modificación:
07/07/2026

CVE-2026-59152

Fecha de publicación:
06/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** LangSmith Client SDKs provide SDK&amp;#39;s for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can send an HTTP request to a server running the LangSmith SDK&amp;#39;s TracingMiddleware can cause that server to read an arbitrary file from its local filesystem and upload the contents to LangSmith as a trace attachment. Depending on how the distributed trace system is deployed, triggering a read may not require authentication. Retrieving the contents requires read access to the LangSmith workspace the traces are sent to. The net effect is a trust-boundary crossing: a party with workspace trace-read access (for example a low-privilege workspace member, a contractor, or a compromised teammate account) gains the ability to read files from any server running TracingMiddleware, a capability outside that workspace&amp;#39;s intended trust boundary. This vulnerability is fixed in 0.8.18.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/07/2026

CVE-2026-58203

Fecha de publicación:
06/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** pydantic-settings provides settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSecretsSettingsSource reads secret values from files in a configured secrets_dir. When secrets_nested_subdir=True, a directory entry inside secrets_dir that is a symbolic link pointing outside secrets_dir is followed, so files outside the configured directory are read into settings values. The same code path bypasses the documented secrets_dir_max_size protection. An attacker or lower-privileged component able to influence entries in the configured secrets directory (for example, a writable or shared secrets mount) can turn this into an unintended local file read into settings and can defeat the advertised loading-size cap. This vulnerability is fixed in 2.14.2.
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/07/2026

CVE-2026-13122

Fecha de publicación:
06/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled
Gravedad CVSS v4.0: MEDIA
Última modificación:
09/07/2026

CVE-2025-53829

Fecha de publicación:
06/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attacker with administrative privileges can exploit a path traversal vulnerability in the system to execute arbitrary code. Upgrade ownCloud 10 to version 10.15.3 or later to receive a patch.
Gravedad CVSS v3.1: ALTA
Última modificación:
08/07/2026

CVE-2025-53830

Fecha de publicación:
06/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud. Versions of Anti-Virus for ownCloud before 1.2.3 are vulnerable to Server-Side Request Forgery (SSRF). This corresponds to versions of ownCloud 10 prior to 10.15.3. Upgrade ownCloud 10 to version 10.15.3 or later or upgrade Anti-Virus for ownCloud 10 to version 1.2.3 or later to receive a fix.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
08/07/2026

CVE-2025-53827

Fecha de publicación:
06/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classic. In versions prior to 10.15.3, the Updater on ownCloud 10 before 10.15.3 has an exposed dangerous method or function. Attackers with administrative privileges may leverage functionality to execute arbitrary code. This issue has been fixed in version 10.15.3.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
08/07/2026

CVE-2025-53828

Fecha de publicación:
06/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing application ownCloud Classic. In SharePoint for ownCloud prior to version 0.4.1, which corresponds to ownCloud 10 prior to 10.15.3, an attacker with administrative privileges can use a SSRF vulnerability in the SharePoint app to execute arbitrary code on the system. Upgrade ownCloud 10 to version 10.15.3 or later to receive SharePoint for ownCloud 0.4.1, the fixed version.
Gravedad CVSS v3.1: ALTA
Última modificación:
08/07/2026