Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2024-23568

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information of software could allow an attacker to determine which vulnerabilities are present in the software, particularly if an outdated software version is in use with published vulnerabilities.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2026-8396

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NetGIS allows Serialized Data External Linking.<br /> <br /> This issue affects NetGIS: from 5.0.66 before 7.2.2.
Gravedad CVSS v3.1: ALTA
Última modificación:
17/07/2026

CVE-2026-7189

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz&amp;#39;s OBS allows Accessing Functionality Not Properly Constrained by ACLs.<br /> <br /> This issue affects Proliz&amp;#39;s OBS: before v3.6.0.
Gravedad CVSS v3.1: ALTA
Última modificación:
17/07/2026

CVE-2026-16014

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the component Login Form. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Gravedad CVSS v4.0: MEDIA
Última modificación:
21/07/2026

CVE-2026-13410

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled.<br /> <br /> The default user agent is initialised with SSL_verify_mode explicitly disabled.<br /> <br /> An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user.
Gravedad CVSS v3.1: ALTA
Última modificación:
17/07/2026

CVE-2026-13082

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets.<br /> <br /> The random method creates the challenge text used for the CAPTCHA by sampling characters from an array using Perl&amp;#39;s built-in rand function, and generates a (by default) six-character string.<br /> <br /> The built-in rand function is unsuitable for security applications because it is predictable and reversible.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2026-16009

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /prescriptionorderdetail.php. The manipulation of the argument delid results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.
Gravedad CVSS v4.0: BAJA
Última modificación:
17/07/2026

CVE-2026-16013

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability has been found in liftoff-sr CIPster up to 632336d414ef708a542377c1aa8d6fdb7c70a760. Affected by this issue is the function CipAppPath::deserialize_symbolic of the file source/src/cip/cipepath.cc. Such manipulation leads to out-of-bounds read. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The name of the patch is 886a4d090e1c5b0475f0b1c2fe0606a8f0d6a519. A patch should be applied to remediate this issue.
Gravedad CVSS v4.0: MEDIA
Última modificación:
17/07/2026

CVE-2026-15943

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. Due to improper validation, Keycloak reuses the existing real secret even if security-sensitive fields like the token URL have been changed, allowing an attacker to redirect and capture the secret.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2026-9602

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Mattermost Desktop App versions
Gravedad CVSS v3.1: MEDIA
Última modificación:
30/07/2026

CVE-2026-8075

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Mattermost Desktop App versions
Gravedad CVSS v3.1: MEDIA
Última modificación:
30/07/2026

CVE-2026-59695

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet in a single request by naming an arbitrarily high gas price.<br /> <br /> When the mpp Elixir library is configured as fee payer (fee_payer: true), MPP.Tempo.Transaction.cosign_fee_payer/3 re-signs the client-supplied base fields of the 0x76 AASigned envelope verbatim, including max_fee_per_gas and max_priority_fee_per_gas, without validating that they are within reasonable bounds. A malicious client embeds arbitrarily large values for these fields in the signed envelope. The server co-signs and broadcasts the transaction. The effective_gas_price billed against the fee-payer wallet is derived from the attacker-supplied ceilings, so the server pays those inflated per-gas rates out of its own wallet. A single crafted request can drain the wallet entirely, after which the server can no longer sponsor gas for legitimate payment requests.<br /> <br /> This issue affects mpp: from 0.2.0 before 0.6.0.
Gravedad CVSS v4.0: ALTA
Última modificación:
17/07/2026