Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-59692

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.
Gravedad CVSS v3.1: ALTA
Última modificación:
19/08/2026

CVE-2026-56288

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) data structures, causing the application to pass a NULL pointer to fwrite() during patch processing.<br /> An attacker can trigger this condition with a malicious patch file, causing the utility to crash and resulting in a denial of service.<br /> <br /> <br /> <br /> This issue has been fixed in the commit e6d6a4e021660679d7fc9150f981d4920f722313
Gravedad CVSS v4.0: MEDIA
Última modificación:
13/07/2026

CVE-2026-56289

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position.<br /> This results in excessive CPU consumption and prevents the process from completing.<br /> An attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination.<br /> <br /> <br /> <br /> This issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9
Gravedad CVSS v4.0: MEDIA
Última modificación:
13/07/2026

CVE-2026-56291

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
24/07/2026

CVE-2026-4298

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. This is due to the dsgvo_reset_policy_service_func() function lacking both capability checks and nonce verification while processing user-supplied parameters to reset plugin options. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset all customized privacy policy content including cookie notices, Google Analytics policies, Facebook policies, and YouTube policies to their default values.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-4275

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Divi Torque Lite – Divi Theme, Divi Builder &amp; Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. This is due to the use of &amp;#39;__return_true&amp;#39; as the permission_callback for the /install_plugin and /activate_plugin REST API endpoints, which bypasses WordPress&amp;#39;s built-in REST API nonce verification. Although the endpoint callbacks contain internal current_user_can() checks, the absence of nonce verification means that a forged cross-site request from a logged-in administrator&amp;#39;s browser will pass the capability check via the admin&amp;#39;s session cookies. This makes it possible for unauthenticated attackers to install arbitrary plugins from WordPress.
Gravedad CVSS v3.1: ALTA
Última modificación:
09/07/2026

CVE-2026-50644

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all rights can inject SQL commands into the audit configuration form which is then saved. The execution is triggered when the audit functionality is accessed (by the attacker or another user).<br /> <br /> This issue was fixed in version 1.56.01.
Gravedad CVSS v4.0: ALTA
Última modificación:
09/07/2026

CVE-2026-12428

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_values() function in the /wp-json/acf-field-blocks/v1/values REST endpoint in versions up to, and including, 1.6.2. The permission_callback only verifies the generic publish_posts capability and the handler passes a user-supplied id parameter directly to get_field_objects() without verifying that the requesting user is authorized to read the target object. This makes it possible for authenticated attackers, with Author-level access and above, to read ACF field values from arbitrary posts (including private posts, drafts, posts by other users, and other ACF-supported objects) that they should not have access to.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-13441

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the &amp;#39;new_event_type_background_color&amp;#39; parameter in all versions up to, and including, 4.3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the plugin&amp;#39;s Guest Submissions setting (allow_submission_by_anonymous_user) to be enabled, which allows unauthenticated attackers to submit event types via the frontend form; when that setting is disabled, exploitation requires at minimum a subscriber-level authenticated account.
Gravedad CVSS v3.1: ALTA
Última modificación:
09/07/2026

CVE-2026-14372

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator &amp; Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteFiles function in all versions up to, and including, 3.1.1 This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config).
Gravedad CVSS v3.1: ALTA
Última modificación:
09/07/2026

CVE-2026-12590

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-parser 1.20.6 and 2.3.0. After the fix, invalid limit values throw a clear error at parser construction time instead of silently disabling enforcement, while null and undefined continue to fall back to the default limit of 100kb. Workarounds: Validate the limit value before passing it to body-parser. For example, parse the value at startup and reject any configuration where the result is null or a non-finite number.
Gravedad CVSS v3.1: BAJA
Última modificación:
10/07/2026

CVE-2026-5793

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper neutralization of input during web page generation (&amp;#39;cross-site scripting&amp;#39;) vulnerability in Inrove Software and Internet Services BiEticaret allows Reflected XSS.<br /> <br /> This issue affects BiEticaret: before v3.3.57.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026