Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-13397

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes.<br /> <br /> The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever.<br /> <br /> Nameless attributes such as "" or unbalanced quotes "" can trigger this condition.<br /> <br /> Note that the latest version available on CPAN is version 0.02. Newer versions are available on the git repository.
Gravedad CVSS v3.1: ALTA
Última modificación:
17/07/2026

CVE-2026-44596

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an unauthenticated remote attacker could perform unlimited password-guessing attempts against any user account, significantly increasing the risk of successful brute-force attacks. This issue is fixed in versions 5.12.7 and 5.13.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2026-3031

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library.<br /> <br /> Image::EPEG includes Epeg 0.9.0 that was last updated in 2004.<br /> <br /> Epeg is a fast JPEG thumbnail library that was once part of the Englightenment Project.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
17/07/2026

CVE-2026-44595

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java, so any authenticated user, even one with low or no privileges, could enumerate all user accounts in the system including their usernames, superuser status, and group memberships. This issue is fixed in versions 5.12.7 and 5.13.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
18/07/2026

CVE-2026-10589

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.
Gravedad CVSS v4.0: MEDIA
Última modificación:
16/07/2026

CVE-2026-10590

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrarily trigger a System Management Interrupt handler.
Gravedad CVSS v4.0: MEDIA
Última modificación:
16/07/2026

CVE-2026-13103

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code.
Gravedad CVSS v4.0: ALTA
Última modificación:
16/07/2026

CVE-2026-10587

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode.
Gravedad CVSS v4.0: MEDIA
Última modificación:
16/07/2026

CVE-2026-10588

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.
Gravedad CVSS v4.0: MEDIA
Última modificación:
16/07/2026

CVE-2025-45870

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated user to exploit path traversal flaws in the fileExt parameter, enabling unauthorized access to sensitive files outside the designated directories.
Gravedad CVSS v3.1: MEDIA
Última modificación:
20/07/2026

CVE-2026-63082

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Perfect Support Ticketing &amp; Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers with Agent-level privileges to manipulate the Support Agent assignment field of tickets by bypassing intended authorization checks. Attackers can add or remove any user, including Superadmin accounts, from the Support Agent field of any ticket to which they are assigned, circumventing role-based access controls.
Gravedad CVSS v4.0: MEDIA
Última modificación:
16/07/2026

CVE-2026-63081

Fecha de publicación:
16/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Perfect Support Ticketing &amp; Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious payloads into the Notes field of assigned support tickets. Attackers can store malicious scripts that execute in the browser context of any user who views the affected ticket notes, including Superadmin users, enabling session hijacking or unauthorized actions on behalf of the victim.
Gravedad CVSS v4.0: MEDIA
Última modificación:
18/07/2026