Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-59235

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Missing Authorization (CWE-862) in BankAccountListController (app/Http/Controllers/Api/BankAccount/BankAccountListController.php), exposed at GET /api/bank-account, in Prospero Flow CRM company_id)->get(), performing only company scoping and no role or permission check before returning the data. This results in the unauthorized disclosure of sensitive banking information (e.g. IBAN, SWIFT/BIC, account identifiers) to users who should not have access to it.
Gravedad CVSS v4.0: ALTA
Última modificación:
15/07/2026

CVE-2026-40633

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-8281

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Gravedad: Pendiente de análisis
Última modificación:
15/07/2026

CVE-2026-57821

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view offices to inject arbitrary SQL via a crafted orderBy value. This is a bypass of the ColumnValidator fix introduced for CVE-2024-32838, which does not detect bare subqueries in the ORDER BY position. This can be leveraged to perform time-based blind SQL injection for data exfiltration. Because the injected query blocks the database connection for its full duration, concurrent exploitation can exhaust the application's database connection pool, resulting in denial of service for other users. Users are recommended to upgrade to a version containing the fix.
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-56287

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sortOrder request parameters are concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view clients to inject arbitrary SQL via a crafted orderBy value. This can be leveraged to perform blind boolean-based data extraction and, on MySQL/MariaDB, to disclose arbitrary files readable by the database process via the LOAD_FILE() function. Users are recommended to upgrade to a version containing the fix
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-49501

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Gravedad CVSS v3.1: MEDIA
Última modificación:
16/07/2026

CVE-2026-57833

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics
Gravedad CVSS v4.0: ALTA
Última modificación:
23/07/2026

CVE-2026-58077

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics
Gravedad CVSS v4.0: ALTA
Última modificación:
23/07/2026

CVE-2026-35152

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are incorporated into the generated SQL query without sufficient validation, allowing an authenticated user with permission to run reports to inject arbitrary SQL via crafted parameter values. This can be leveraged to perform unauthorized access to data beyond what the report was designed to expose. Users are recommended to upgrade to a version containing the fix.
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-57831

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection.
Gravedad CVSS v4.0: ALTA
Última modificación:
23/07/2026

CVE-2026-57832

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in EDocman
Gravedad CVSS v4.0: ALTA
Última modificación:
23/07/2026

CVE-2026-15804

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can inject SQL commands via specific parameters, thereby compromising the confidentiality, integrity, and availability of database data.
Gravedad CVSS v4.0: ALTA
Última modificación:
15/07/2026