Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-16016

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was identified in poco-ai poco-claw up to 0.5.4. This issue affects the function run_task of the file executor/app/api/v1/task.py. The manipulation of the argument callback_url leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The reported GitHub issue was closed automatically due to inactivity.
Gravedad CVSS v4.0: MEDIA
Última modificación:
17/07/2026

CVE-2026-16015

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of the file executor_manager/app/api/v1/tasks.py of the component executor_manager API. Executing a manipulation can lead to missing authentication. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.5.7 is able to resolve this issue. This patch is called 67fcc88505c57f77d3fcf04eb5b89425b10cbf48. It is recommended to upgrade the affected component.
Gravedad CVSS v4.0: BAJA
Última modificación:
17/07/2026

CVE-2026-16072

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application programming interface. By using this link, the administrator can create new user accounts and add them to the organization without having the required user management permissions or access to the invited email account. This allows an administrator to bypass security boundaries and add unauthorized members to an organization.
Gravedad CVSS v3.1: MEDIA
Última modificación:
21/07/2026

CVE-2025-60357

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEvent/list endpoint.
Gravedad CVSS v3.1: ALTA
Última modificación:
17/07/2026

CVE-2024-23578

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard).
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2024-42214

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web server which allows an attacker to narrow and intensify their efforts.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2024-23569

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2024-23570

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on his malicious site. The attacker can then launch a Clickjacking attack, which may lead to Phishing, Cross-Site Request Forgery, sensitive information leakage and more.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2024-23571

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields should be cached. If sensitive information in application responses is stored in the local cache, then this may be retrieved by other users who have access to the same computer at a future time.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2024-23572

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2024-23573

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be considered a type of man-in-the-middle attack.
Gravedad CVSS v3.1: BAJA
Última modificación:
17/07/2026

CVE-2024-23574

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid users in a system
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026