Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-9027

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification of Cryptographic Signature in all versions up to, and including, 2.7.4. The `corvuspay_success_handler` function registers the REST endpoint `POST /wp-json/corvuspay/success/` with `'permission_callback' => '__return_true'`, and while it calls `$this->client->validate->signature()` and stores the boolean result in `$res`, the result is never evaluated in a conditional — it is only written to the debug log — causing execution to unconditionally reach `$order->payment_complete()` regardless of whether the cryptographic signature is valid. This makes it possible for unauthenticated attackers to mark any pending WooCommerce order as fully paid by sending a POST request to the success endpoint containing an arbitrary or forged signature value, allowing them to obtain goods or services without payment. Because WooCommerce order IDs are sequential integers, target orders are trivially enumerable via the `order_number` POST parameter, requiring no prior knowledge of the victim order.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-9028

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.7.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to cancel any WooCommerce order placed via the CorvusPay payment method by supplying an arbitrary order number to the /wp-json/corvuspay/cancel/ REST endpoint.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-9235

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check and missing nonce verification on the create_label() and delete_label() functions in versions up to, and including, 2.2.3. These functions are wired to the wp_ajax_dhlpwc_label_create and wp_ajax_dhlpwc_label_delete hooks and act on an attacker-supplied post_id (WooCommerce order ID). This makes it possible for authenticated attackers, with Subscriber-level access and above, to create or delete DHL shipping labels associated with any WooCommerce order on the site.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-9240

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the updateShippingMethod() function (registered to the wp_ajax_lpc_order_affect AJAX action) in versions up to, and including, 2.9.0. This is due to the handler performing no current_user_can() capability check and no nonce verification before reading an attacker-supplied order_id and modifying that order's shipping method, pickup-point meta, and shipping address. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create or modify the shipment information (shipping method, pickup relay data, and shipping address) of arbitrary WooCommerce orders, including orders placed by other users.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-9237

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete, archive, unarchive, and duplicate arbitrary job listings — along with their associated stages, meta, addresses, and applications — by supplying an arbitrary integer job_id. The nonce verified by Dispatcher::dispatch() is exposed to all authenticated front-end visitors via wp_head script localization, meaning subscribers can trivially obtain it and satisfy the nonce check without possessing any elevated privilege.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-9021

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Easy Invoice plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.19. This is due to the plugin registering the easy_invoice_accept_quote and easy_invoice_decline_quote AJAX actions via wp_ajax_nopriv_ hooks and relying solely on a quote-scoped nonce that is rendered into the publicly accessible single quote template, combined with an ownership check that is gated behind an off-by-default Pro option (easy_invoice_pro_restrict_quote_to_client). This makes it possible for unauthenticated attackers to accept or decline arbitrary published quotes — and, depending on the configured accept action, automatically convert them into invoices (and even email them to the client) — by harvesting the per-quote nonce from the public quote page and submitting it to admin-ajax.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-58303

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Stack-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.<br /> <br /> This issue affects Escargot: before b30b63fc63b403907d8137da1c65aaa4521fe74e.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-58304

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.<br /> <br /> This issue affects Escargot: before 779f6bedf58f334dec64b0a51ebb724b4708b84a.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-58305

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Access of resource using incompatible type (&amp;#39;type confusion&amp;#39;) vulnerability in Samsung Open Source Escargot allows Pointer Manipulation.<br /> <br /> This issue affects Escargot: before 779f6bedf58f334dec64b0a51ebb724b4708b84a.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-58306

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.<br /> <br /> This issue affects Escargot: before ef525f337fafddecde77a3c426212a84bb20cb98.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-58307

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Data Manipulation.<br /> <br /> This issue affects Escargot: before 2dee22f5c7b8bf31cb7252d7731fae8c07f2842c.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-59691

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A heap buffer overflow vulnerability was found in GStreamer&amp;#39;s rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type mismatch causes an out-of-bounds heap write that can lead to denial of service (process crash) and potential memory corruption.
Gravedad CVSS v3.1: ALTA
Última modificación:
19/08/2026