Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2024-23577

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary hosts when requested in http protocol. When an application doesn’t adequately validate or sanitize this header, it can lead to several security risks, including Host header poisoning, server misconfigurations.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2024-23564

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwords to user emails.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
17/07/2026

CVE-2024-23565

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b e a human or an automated process such as a virus or bot. This could be used to cause a denial of service, compromise program logic or other consequences.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2024-23566

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues like brute force , automated attacks & account enumeration
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2024-23567

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data passed in this manner can be exposed because it may end up stored in unintended locations, including server logs, local browser history and proxy logs.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2024-23568

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information of software could allow an attacker to determine which vulnerabilities are present in the software, particularly if an outdated software version is in use with published vulnerabilities.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2026-8396

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NetGIS allows Serialized Data External Linking.<br /> <br /> This issue affects NetGIS: from 5.0.66 before 7.2.2.
Gravedad CVSS v3.1: ALTA
Última modificación:
17/07/2026

CVE-2026-7189

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz&amp;#39;s OBS allows Accessing Functionality Not Properly Constrained by ACLs.<br /> <br /> This issue affects Proliz&amp;#39;s OBS: before v3.6.0.
Gravedad CVSS v3.1: ALTA
Última modificación:
17/07/2026

CVE-2026-16014

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the component Login Form. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Gravedad CVSS v4.0: MEDIA
Última modificación:
21/07/2026

CVE-2026-13410

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled.<br /> <br /> The default user agent is initialised with SSL_verify_mode explicitly disabled.<br /> <br /> An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user.
Gravedad CVSS v3.1: ALTA
Última modificación:
17/07/2026

CVE-2026-13082

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets.<br /> <br /> The random method creates the challenge text used for the CAPTCHA by sampling characters from an array using Perl&amp;#39;s built-in rand function, and generates a (by default) six-character string.<br /> <br /> The built-in rand function is unsuitable for security applications because it is predictable and reversible.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2026-16009

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /prescriptionorderdetail.php. The manipulation of the argument delid results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.
Gravedad CVSS v4.0: BAJA
Última modificación:
17/07/2026