Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-63093

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a crafted repository, Cursor automatically resolves and executes the workspace-resident git.exe during IDE startup and on a recurring timed cadence without any user interaction, running the malicious binary under the privileges of the current user.
Gravedad CVSS v4.0: ALTA
Última modificación:
17/07/2026

CVE-2026-63094

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** SigNoz before 0.134.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session tokens from any user on instances configured with Google OAuth, SAML, or OIDC. Attackers can call the unauthenticated sessions context endpoint with a ref parameter pointing to an attacker-controlled host, deliver the resulting crafted login URL to a victim, and receive the victim's access and refresh tokens when they complete SSO authentication.
Gravedad CVSS v4.0: ALTA
Última modificación:
27/07/2026

CVE-2026-16017

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. Impacted is the function list/remove of the file tools/tool_cron.go of the component cron Chat Tool. The manipulation results in missing authorization. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The reported GitHub issue was closed with the label "not planned".
Gravedad CVSS v4.0: BAJA
Última modificación:
17/07/2026

CVE-2026-51082

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4.19; qemu-server 9.x before 9.1.7 and 8.x before 8.4.7; and pve-container before 6.1.3 (PVE 9.x) and before 5.3.4 (PVE 8.x) allows an attacker with privileges to call "vncproxy" to hijack a VNC session that is established in parallel by a different user for a different VM.
Gravedad CVSS v3.1: ALTA
Última modificación:
17/07/2026

CVE-2026-51081

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2026-51083

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privileges to obtain hashed passwords via the cloudinit/dump API.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2026-16089

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be redeemed by their own client, potentially allowing them to obtain access tokens for a victim's identity.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/07/2026

CVE-2026-12705

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE).<br /> <br /> This issue affects KNX Update Tool (ABB): through 2.0.175; KNX Update Tool (BJE): through 2.0.175.
Gravedad CVSS v4.0: MEDIA
Última modificación:
17/07/2026

CVE-2026-7488

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data.<br /> <br /> This issue affects E-Commerce: through 03062026.
Gravedad CVSS v3.1: ALTA
Última modificación:
17/07/2026

CVE-2026-9592

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** SEPPmail Secure Email Gateway &amp; SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay &amp; hijack a user session in the GINA web portal, as the session token is disclosed inside the URL and a HTTP header.
Gravedad CVSS v4.0: ALTA
Última modificación:
17/07/2026

CVE-2026-51080

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
17/07/2026

CVE-2026-16016

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was identified in poco-ai poco-claw up to 0.5.4. This issue affects the function run_task of the file executor/app/api/v1/task.py. The manipulation of the argument callback_url leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The reported GitHub issue was closed automatically due to inactivity.
Gravedad CVSS v4.0: MEDIA
Última modificación:
17/07/2026