Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-60119

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Hi.Events before 1.11.0 contains a cross-site scripting vulnerability that allows authenticated attackers with event creation or edit permissions to inject arbitrary HTML and JavaScript by embedding a malicious event title containing the sequence, which is not escaped by JSON.stringify() when embedded in inline script tags. Attackers can craft an event title that breaks out of the script context in the application/ld+json structured data block or server-side rehydrated state, causing the payload to execute in the browser of any user who views the public event page, including unauthenticated visitors and authenticated administrators.
Gravedad CVSS v4.0: MEDIA
Última modificación:
15/07/2026

CVE-2026-7494

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0 through versions prior to 3.94.0.
Gravedad CVSS v4.0: MEDIA
Última modificación:
15/07/2026

CVE-2026-62644

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
Gravedad CVSS v3.1: MEDIA
Última modificación:
20/07/2026

CVE-2026-62643

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: this issue exists because of insufficient fixes for CVE-2026-35540 and CVE-2026-48843.
Gravedad CVSS v3.1: ALTA
Última modificación:
20/07/2026

CVE-2026-62642

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.
Gravedad CVSS v3.1: MEDIA
Última modificación:
20/07/2026

CVE-2026-62641

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.
Gravedad CVSS v3.1: MEDIA
Última modificación:
20/07/2026

CVE-2026-59841

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-60081

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** DBI::ProfileData versions before 1.651 for Perl do not limit the path index.<br /> <br /> The path index column of profile dump files is used to allocate an array of data for the parser. An unbounded value allows an attacker to specify a large index and consume available memory.
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-60082

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row.<br /> <br /> When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index.<br /> <br /> This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
15/07/2026

CVE-2026-59839

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A improper limitation of a pathname to a restricted directory (&amp;#39;path traversal&amp;#39;) vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.8.0, FortiPAM 1.7.0 through 1.7.2, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to execute unauthorized code or commands via
Gravedad CVSS v3.1: MEDIA
Última modificación:
11/08/2026

CVE-2026-59840

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to information disclosure via
Gravedad CVSS v3.1: MEDIA
Última modificación:
11/08/2026

CVE-2026-59203

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow&amp;#39;s EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing a crafted EPS file to cause Image.open() to seek backwards to the same directive and parse it repeatedly in an infinite loop. This issue is fixed in version 12.3.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
15/07/2026