Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-15583

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services, including cloud metadata endpoints.
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-14251

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped Argo CD instance can trigger deletion of a ClusterRole owned by a cluster-scoped Argo CD instance by crafting a name collision, resulting in a denial of service.
Gravedad CVSS v3.1: ALTA
Última modificación:
16/07/2026

CVE-2026-42936

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privilege of the user invoking the installer.
Gravedad CVSS v4.0: ALTA
Última modificación:
15/07/2026

CVE-2026-12512

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform UNION-based SQL injection and read arbitrary data from the database, including password hashes.
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-11580

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, allowing users with Contributor-level access or above to duplicate any post (regardless of owner, post type, or status) into a published post they own and read its private post metadata, including secrets stored by other Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17.
Gravedad CVSS v3.1: MEDIA
Última modificación:
15/07/2026

CVE-2026-12281

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carries identity headers as an authenticated session without verifying them. On a deployment where untrusted client headers reach the application, an unauthenticated attacker can log in with forged identity headers and, when automatic account creation and the default administrator role mapping are enabled, create and sign in as a new administrator. Exploitation requires the non-default HTTP header attribute mode, an empty or absent spoof key, automatic account creation enabled, and a deployment that does not strip untrusted client headers before they reach the application.
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-11579

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing form configured with a file-upload field, accepting uploads regardless of whether any such form exists, which allows unauthenticated users to upload files to the WordPress Media Library; the uploads are limited to WordPress's default-allowed MIME types, so this does not lead to code execution.
Gravedad CVSS v3.1: MEDIA
Última modificación:
15/07/2026

CVE-2026-8919

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application’s local service endpoint. This can result in information disclosure or data tampering, may cause GameSDK to become unavailable, and may also enable access to the victim’s information on other services.<br /> Refer to the &amp;#39; Security Update for ASUS GameSDK  &amp;#39; section on the ASUS Security Advisory for more information.
Gravedad CVSS v4.0: ALTA
Última modificación:
15/07/2026

CVE-2026-8920

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this can also cause a single feature to become unavailable .<br /> Refer to the &amp;#39; Security Update for Aura Wallpaper Service &amp;#39; section on the ASUS Security Advisory for more information.
Gravedad CVSS v4.0: ALTA
Última modificación:
15/07/2026

CVE-2026-15029

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced memory protections.<br /> Refer to the &amp;#39; <br /> Security Update for ASUS System Control Interface  &amp;#39; section on the ASUS Security Advisory for more information.
Gravedad CVSS v4.0: ALTA
Última modificación:
15/07/2026

CVE-2026-15030

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL request that bypasses the validation.<br /> Refer to the &amp;#39; Security Update for ASUS System Control Interface  &amp;#39; section on the ASUS Security Advisory for more information.
Gravedad CVSS v4.0: MEDIA
Última modificación:
15/07/2026

CVE-2026-13585

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a Denial of Service (DoS) on the system.<br /> Refer to the &amp;#39; <br /> Security Update for ASUS System Control Interface  &amp;#39; section on the ASUS Security Advisory for more information.
Gravedad CVSS v4.0: ALTA
Última modificación:
21/07/2026