Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2024-32386

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the SNMP update mechanism.
Gravedad CVSS v3.1: ALTA
Última modificación:
17/07/2026

CVE-2024-32387

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the community string component.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2024-32389

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the update URLs component.
Gravedad CVSS v3.1: BAJA
Última modificación:
17/07/2026

CVE-2024-34268

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow unsecured bluetooth connections. This vulnerability allows attackers to gain full access to the device without authentication.
Gravedad CVSS v3.1: ALTA
Última modificación:
17/07/2026

CVE-2024-32385

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via a boardID and revisionID components
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2026-62963

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidirectional WebSocket transport with uni_websocket.compression enabled enforced uni_websocket.message_size_limit against compressed wire-frame length in internal/websocket/conn.go advanceFrame, but ReadMessage used io.ReadAll after decompression without an output cap, allowing unauthenticated requests to /connection/uni_websocket to trigger large memory and CPU consumption. This issue is fixed in version 6.8.4.
Gravedad CVSS v4.0: ALTA
Última modificación:
17/07/2026

CVE-2026-63089

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers to recover WireGuard peer credentials by brute-forcing a keyspace of at most 1000 candidate tokens per client ID, as the token is computed using CRC32 over a random value constrained to 0-999. Attackers can enumerate candidate tokens against the unauthenticated /cnf/:oneTimeLink route, which lacks rate limiting and does not validate token expiration, to obtain a peer's PrivateKey and PresharedKey and impersonate that peer on the VPN network.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
18/07/2026

CVE-2026-63397

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL schema that is passed to genql to inject arbitrary JavaScript or TypeScript. The malicious code is injected into the generated schema.ts file and executes when the genql client is bundled and imported.
Gravedad CVSS v4.0: ALTA
Última modificación:
21/07/2026

CVE-2026-62309

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when the proxyproto plugin is enabled because plugin/pkg/proxyproto/proxyproto.go PacketConn.ReadFrom handles a PROXY v2 header with non-UDP transport such as family byte 0x11, reassigns addr from a nil readFrom result after parseProxyProtocol errors, and calls addr.String() in the warning log before ServeDNS recovery applies. This issue is fixed in version 1.14.4.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-62994

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreDNS zone can trigger a panic when CoreDNS is configured with k8s_external headless-service zone transfers and Kubernetes contains a headless service endpoint with no declared ports; plugin/kubernetes/object/endpoint.go creates Port: -1, plugin/k8s_external/msg_to_dns.go skips that service, plugin/k8s_external/transfer.go sends an empty []dns.RR batch, and plugin/transfer/transfer.go indexes records[0] without checking the batch is non-empty. This issue is fixed in version 1.14.5.
Gravedad CVSS v3.1: BAJA
Última modificación:
22/07/2026

CVE-2026-60140

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An out-of-bounds read vulnerability in the Productivity Suite allows a <br /> local attacker to trigger kernel memory corruption by sending a crafted <br /> IOCTL request. This can lead to exposing sensitive information or <br /> causing the affected product to become unstable or unavailable.
Gravedad CVSS v4.0: MEDIA
Última modificación:
17/07/2026

CVE-2026-61389

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An out-of-bounds write vulnerability in the Productivity Suite allows a <br /> local attacker to trigger kernel memory corruption via a crafted IOCTL <br /> request, potentially resulting in privilege escalation or system <br /> instability.
Gravedad CVSS v4.0: ALTA
Última modificación:
17/07/2026