Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-16089

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be redeemed by their own client, potentially allowing them to obtain access tokens for a victim's identity.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/07/2026

CVE-2026-12705

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE).<br /> <br /> This issue affects KNX Update Tool (ABB): through 2.0.175; KNX Update Tool (BJE): through 2.0.175.
Gravedad CVSS v4.0: MEDIA
Última modificación:
17/07/2026

CVE-2026-7488

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data.<br /> <br /> This issue affects E-Commerce: through 03062026.
Gravedad CVSS v3.1: ALTA
Última modificación:
17/07/2026

CVE-2026-9592

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** SEPPmail Secure Email Gateway &amp; SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay &amp; hijack a user session in the GINA web portal, as the session token is disclosed inside the URL and a HTTP header.
Gravedad CVSS v4.0: ALTA
Última modificación:
17/07/2026

CVE-2026-51080

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
17/07/2026

CVE-2026-16016

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was identified in poco-ai poco-claw up to 0.5.4. This issue affects the function run_task of the file executor/app/api/v1/task.py. The manipulation of the argument callback_url leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The reported GitHub issue was closed automatically due to inactivity.
Gravedad CVSS v4.0: MEDIA
Última modificación:
17/07/2026

CVE-2026-16015

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of the file executor_manager/app/api/v1/tasks.py of the component executor_manager API. Executing a manipulation can lead to missing authentication. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.5.7 is able to resolve this issue. This patch is called 67fcc88505c57f77d3fcf04eb5b89425b10cbf48. It is recommended to upgrade the affected component.
Gravedad CVSS v4.0: BAJA
Última modificación:
17/07/2026

CVE-2026-16072

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application programming interface. By using this link, the administrator can create new user accounts and add them to the organization without having the required user management permissions or access to the invited email account. This allows an administrator to bypass security boundaries and add unauthorized members to an organization.
Gravedad CVSS v3.1: MEDIA
Última modificación:
21/07/2026

CVE-2025-60357

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEvent/list endpoint.
Gravedad CVSS v3.1: ALTA
Última modificación:
17/07/2026

CVE-2024-23578

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard).
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2024-42214

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web server which allows an attacker to narrow and intensify their efforts.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2024-23569

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026