Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-11917

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitrary files to restricted system directories outside of the application's intended directory.
Gravedad CVSS v4.0: ALTA
Última modificación:
14/07/2026

CVE-2026-11944

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that allows an authenticated attacker to read arbitrary files on the server via crafted path traversal sequences.
Gravedad CVSS v4.0: MEDIA
Última modificación:
14/07/2026

CVE-2025-53379

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request.
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2025-43892

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.
Gravedad CVSS v3.1: MEDIA
Última modificación:
11/08/2026

CVE-2025-62675

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker in possession of a valid web filter override token to inject arbitrary headers via tricking a user into clicking on a crafted link.
Gravedad CVSS v3.1: BAJA
Última modificación:
11/08/2026

CVE-2025-62826

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker able to intercept and modify a user's captive portal authentication request to inject arbitrary headers via crafted HTTP requests.
Gravedad CVSS v3.1: BAJA
Última modificación:
11/08/2026

CVE-2025-11698

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF).
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
14/07/2026

CVE-2026-9653

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after.
Gravedad CVSS v4.0: ALTA
Última modificación:
14/07/2026

CVE-2026-8590

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Vulnerability in Spotfire Spotfire Enterprise (Spotfire Server modules), Spotfire Spotfire Enterprise with External Consumers (Spotfire Server modules), Spotfire Spotfire on Kubernetes (Spotfire Server modules).<br /> <br /> This issue affects Spotfire Enterprise: through 14.0.12, through 14.4.2, through 14.5.0, through 14.6.1, through 14.6.2, through 14.7.0, through 14.8.0; Spotfire Enterprise with External Consumers: through 14.0.12, through 14.5.0, through 14.6.0, through 14.6.1, through 14.6.2, through 14.7.0, through 14.8.0; Spotfire on Kubernetes: through 4.2.0, 5.0.X, 6.0.X.
Gravedad CVSS v4.0: ALTA
Última modificación:
15/07/2026

CVE-2026-9140

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose communication. A power cycle is required to recover.
Gravedad CVSS v4.0: ALTA
Última modificación:
14/07/2026

CVE-2026-60114

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attackers with access to the restore functionality to write files to arbitrary locations by uploading crafted JSON backup files with unvalidated keys used to construct file paths. Attackers can exploit the lack of key validation in the JSON restore process, combined with the absence of a required passphrase in the default configuration or the default passphrase &amp;#39;opendoor&amp;#39;, to write arbitrary JSON files outside the intended data directory.
Gravedad CVSS v4.0: ALTA
Última modificación:
16/07/2026

CVE-2026-58475

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript by supplying malicious script payloads within program names submitted via HTTP requests. Attackers can exploit the lack of output encoding on rendered program names to execute arbitrary JavaScript in the browsers of any users viewing the affected page, with exploitation facilitated by the absence of a required passphrase or the default passphrase &amp;#39;opendoor&amp;#39;.
Gravedad CVSS v4.0: MEDIA
Última modificación:
15/07/2026