Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-94533

Fecha de publicación:
21/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticated users to download arbitrary attachments. Attackers can retrieve other users' stored files by supplying valid attachment identifiers to the /anyone/file/down and /anyone/file/download endpoints, as the application never validates file ownership against the created_by column.
Gravedad CVSS v4.0: ALTA
Última modificación:
22/09/2026

CVE-2026-94534

Fecha de publicación:
21/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing authenticated attackers to modify arbitrary user profiles. Attackers can supply target user IDs in request bodies to rewrite profile fields including nickname, ID card, sex, nation, education, work description, and avatar attachments of other users.
Gravedad CVSS v4.0: ALTA
Última modificación:
22/09/2026

CVE-2026-94535

Fecha de publicación:
21/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications. Attackers can call the DELETE /anyone/extendNotice/deleteMyNotice endpoint with arbitrary notice IDs to permanently remove notifications belonging to other users without recipient validation.
Gravedad CVSS v4.0: ALTA
Última modificación:
22/09/2026

CVE-2026-94536

Fecha de publicación:
21/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing authenticated users to read any employee's roles and permissions. Attackers can supply arbitrary employeeId values to enumerate other employees' role codes, permission codes, and complete front-end router trees without authorization checks.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/09/2026

CVE-2026-94622

Fecha de publicación:
21/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. Attackers can send requests with incomplete kv_transfer_params dictionary entries to trigger an uncaught KeyError in EngineCore scheduling, causing the decode engine to terminate and making all routed requests fail until manual restart.
Gravedad CVSS v4.0: ALTA
Última modificación:
29/09/2026

CVE-2026-88756

Fecha de publicación:
21/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Pagekit CMS
Gravedad CVSS v3.1: MEDIA
Última modificación:
24/09/2026

CVE-2026-88738

Fecha de publicación:
21/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An attacker with administrative privileges can upload a server-side executable file. The uploaded file is stored in a web-accessible executable location and can be accessed directly over HTTP without authentication, resulting in remote code execution.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-79079

Fecha de publicación:
21/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** An issue in CrossWire Xiphos
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-93340

Fecha de publicación:
21/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting the client-supplied origin parameter in the forgot_password endpoint without server-side validation. Attackers can send a crafted request specifying an attacker-controlled origin, causing the victim to receive a poisoned reset link that discloses the session token to the attacker, enabling full account takeover including administrator accounts.
Gravedad CVSS v4.0: ALTA
Última modificación:
23/09/2026

CVE-2026-78806

Fecha de publicación:
21/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive information via the PerformCommissioningStep function in the ChipDeviceController.cpp component
Gravedad CVSS v3.1: MEDIA
Última modificación:
24/09/2026

CVE-2026-61851

Fecha de publicación:
21/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's runQuery() implementation in server/modules/ai/orchestrator/tools/runQuery.js attempts to enforce read-only database access with a blocklist containing only seven SQL keywords. An authenticated user with AI feature access can submit dangerous statements or database functions that are absent from the read-only keyword blocklist, causing them to execute without SQL injection or keyword-obfuscation techniques. Depending on the database engine, configuration, and database-user privileges, this can expose or write files, access internal network resources, change database privileges, execute commands, or alter data. This issue is fixed in version 5.2.2.
Gravedad CVSS v4.0: MEDIA
Última modificación:
24/09/2026

CVE-2026-61852

Fecha de publicación:
21/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's runQuery() implementation in server/modules/ai/orchestrator/tools/runQuery.js interpolates the AI tool's row_limit parameter into a SQL LIMIT clause without runtime integer validation. The read-only keyword check runs before this value is appended, so an authenticated user who can influence a model-generated non-integer row_limit can add SQL that bypasses the earlier check. Successful exploitation can execute arbitrary statements against the connected database, including reading or changing data and, where database permissions permit, accessing files or executing operating-system commands. This issue is fixed in version 5.2.2.
Gravedad CVSS v4.0: MEDIA
Última modificación:
24/09/2026