Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-11580

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, allowing users with Contributor-level access or above to duplicate any post (regardless of owner, post type, or status) into a published post they own and read its private post metadata, including secrets stored by other Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17.
Gravedad CVSS v3.1: MEDIA
Última modificación:
15/07/2026

CVE-2026-12281

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carries identity headers as an authenticated session without verifying them. On a deployment where untrusted client headers reach the application, an unauthenticated attacker can log in with forged identity headers and, when automatic account creation and the default administrator role mapping are enabled, create and sign in as a new administrator. Exploitation requires the non-default HTTP header attribute mode, an empty or absent spoof key, automatic account creation enabled, and a deployment that does not strip untrusted client headers before they reach the application.
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-11579

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing form configured with a file-upload field, accepting uploads regardless of whether any such form exists, which allows unauthenticated users to upload files to the WordPress Media Library; the uploads are limited to WordPress's default-allowed MIME types, so this does not lead to code execution.
Gravedad CVSS v3.1: MEDIA
Última modificación:
15/07/2026

CVE-2026-8919

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application’s local service endpoint. This can result in information disclosure or data tampering, may cause GameSDK to become unavailable, and may also enable access to the victim’s information on other services.<br /> Refer to the &amp;#39; Security Update for ASUS GameSDK  &amp;#39; section on the ASUS Security Advisory for more information.
Gravedad CVSS v4.0: ALTA
Última modificación:
15/07/2026

CVE-2026-8920

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this can also cause a single feature to become unavailable .<br /> Refer to the &amp;#39; Security Update for Aura Wallpaper Service &amp;#39; section on the ASUS Security Advisory for more information.
Gravedad CVSS v4.0: ALTA
Última modificación:
15/07/2026

CVE-2026-15029

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced memory protections.<br /> Refer to the &amp;#39; <br /> Security Update for ASUS System Control Interface  &amp;#39; section on the ASUS Security Advisory for more information.
Gravedad CVSS v4.0: ALTA
Última modificación:
15/07/2026

CVE-2026-15030

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL request that bypasses the validation.<br /> Refer to the &amp;#39; Security Update for ASUS System Control Interface  &amp;#39; section on the ASUS Security Advisory for more information.
Gravedad CVSS v4.0: MEDIA
Última modificación:
15/07/2026

CVE-2026-13385

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execute arbitrary command via a spoofed server.<br /> Refer to the &amp;#39; <br /> Security Update for ASUS Router Firmware  &amp;#39; section on the ASUS Security Advisory for more information.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
16/07/2026

CVE-2026-13585

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a Denial of Service (DoS) on the system.<br /> Refer to the &amp;#39; <br /> Security Update for ASUS System Control Interface  &amp;#39; section on the ASUS Security Advisory for more information.
Gravedad CVSS v4.0: ALTA
Última modificación:
21/07/2026

CVE-2026-11851

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models allows a remote authenticated user to disclose confidential information via a crafted request that bypasses existing input validation<br /> Refer to the &amp;#39; <br /> Security Update for ASUS Router Firmware &amp;#39; section on the ASUS Security Advisory for more information.
Gravedad CVSS v4.0: MEDIA
Última modificación:
15/07/2026

CVE-2026-9770

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem<br /> that is shared across devices.  An<br /> attacker with access to the firmware image can extract the embedded key.  <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> Successful<br /> exploitation may allow an unauthenticated attacker on the same network to use<br /> this key in the web management service, compromising the confidentiality of<br /> encrypted communications. This may enable passive decryption of traffic or<br /> active man-in-the-middle (MITM) attacks
Gravedad CVSS v4.0: ALTA
Última modificación:
15/07/2026

CVE-2026-13230

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes<br /> sensitive geolocation information without requiring authentication. This issue<br /> allows an attacker on the same local network to retrieve geolocation-related<br /> data through crafted responses.<br /> <br /> The<br /> vulnerability impacts confidentiality only, with no evidence of integrity of<br /> availability impact.
Gravedad CVSS v4.0: MEDIA
Última modificación:
15/07/2026