Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-8306

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper neutralization of input during web page generation (&amp;#39;cross-site scripting&amp;#39;) vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Stored XSS.<br /> <br /> This issue affects Access Control System (GKS): before Version 2.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/07/2026

CVE-2026-57871

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overwrite system files.<br /> <br /> This issue affects MicroRealEstate: through 1.0.0-alpha3.
Gravedad CVSS v4.0: ALTA
Última modificación:
07/07/2026

CVE-2026-58315

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Cross-site request forgery vulnerability exists in SEIKO EPSON Web Config. If a user views a malicious page while logged into Web Config, unintended operations may be performed.
Gravedad CVSS v4.0: MEDIA
Última modificación:
24/07/2026

CVE-2026-12375

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor&amp;#39;s uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthenticated attackers an administrator session on affected sites and beacons the site&amp;#39;s secret keys and administrator details to attacker-controlled servers.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
07/07/2026

CVE-2026-4375

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are added adding to a blog, for example using a vulnerability where unclosed extensions from wordpress.org can be installed by unauthorized users.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
07/07/2026

CVE-2026-57867

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit adversaries targeting MicroRealEstate deployments to brute-force One-Time Passwords (OTP) to log in as any user. This issue affects MicroRealEstate: through 1.0.0-alpha3.
Gravedad CVSS v4.0: ALTA
Última modificación:
07/07/2026

CVE-2026-57868

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** MicroRealEstate is affected by broken object-level access controls in PDF generator functionality.<br /> <br /> This issue affects MicroRealEstate: through 1.0.0-alpha3.
Gravedad CVSS v4.0: ALTA
Última modificación:
07/07/2026

CVE-2026-57869

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents uploaded by landlords or tenants without authorization.<br /> <br /> This issue affects MicroRealEstate: through 1.0.0-alpha3.
Gravedad CVSS v4.0: ALTA
Última modificación:
07/07/2026

CVE-2026-57870

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document templates used by other organizations without authorization.<br /> <br /> This issue affects MicroRealEstate: through 1.0.0-alpha3.
Gravedad CVSS v4.0: MEDIA
Última modificación:
07/07/2026

CVE-2026-14345

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WPFunnels – Funnel Builder for WooCommerce with Checkout &amp; One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 via the &amp;#39;postData&amp;#39; parameter parameter. This is due to unsanitized write of attacker-controlled postData values into a PHP-includeable .log file combined with the use of include_once to render that file in wpfnl_show_log. This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires that the Log Settings "Enable Logs" toggle is on and that an administrator subsequently opens the polluted log file via the plugin&amp;#39;s Log Settings View UI; however, the nonce required to reach the optin endpoint is publicly emitted on every funnel step page, so the injection step itself is fully unauthenticated.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
08/07/2026

CVE-2026-12277

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user input before deleting the referenced file, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php) when guest upload mode is enabled. Deleting wp-config.php forces the site into its setup routine, which can be leveraged toward a full site takeover.
Gravedad CVSS v3.1: ALTA
Última modificación:
07/07/2026

CVE-2026-10834

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile image path before moving the file, allowing authenticated users with subscriber-level access and above to relocate arbitrary files within the WordPress uploads directory into their own profile-image path. This removes the targeted media from its original location and can break content across the site.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026