Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-94056

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
Gravedad CVSS v3.1: ALTA
Última modificación:
24/09/2026

CVE-2026-94055

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.
Gravedad CVSS v3.1: BAJA
Última modificación:
24/09/2026

CVE-2026-94054

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.
Gravedad CVSS v3.1: ALTA
Última modificación:
24/09/2026

CVE-2026-93991

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers with namespace-scoped list permissions can use a negated namespace field selector to retrieve archived workflows from all other namespaces, exposing spec arguments, parameter values, and annotations.
Gravedad CVSS v4.0: ALTA
Última modificación:
22/09/2026

CVE-2026-93992

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing directory traversal sequences that bypass validation, enabling file write operations when users download and extract archives with AutoExtract enabled.
Gravedad CVSS v4.0: ALTA
Última modificación:
22/09/2026

CVE-2026-93993

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe.
Gravedad CVSS v4.0: ALTA
Última modificación:
22/09/2026

CVE-2026-93989

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). Attackers can supply out-of-bounds token indices that corrupt logits memory of concurrent requests, causing different in-flight HTTP requests to return incorrect tokens.
Gravedad CVSS v4.0: BAJA
Última modificación:
28/09/2026

CVE-2026-93990

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/09/2026

CVE-2026-93956

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by this issue is the function SearchEngine::buildHighlights of the file src/SearchEngine.php of the component Search Engine. Executing a manipulation of the argument Query can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 1.1.3 can resolve this issue. This patch is called 0b2fae333d6b022da7ed4c43e2d41aa03f91dff3. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Gravedad CVSS v4.0: BAJA
Última modificación:
21/09/2026

CVE-2026-93955

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the function streamFileToResponse of the file backend/src/main/java/org/booklore/controller/KoboController.java of the component Download Endpoint. Performing a manipulation of the argument bookId results in authorization bypass. The attack may be initiated remotely. The exploit is now public and may be used. Issue #2431 is closed as completed, but its only comment states that the issue “has already been reported elsewhere.” No fixing commit or pull request is identified there.
Gravedad CVSS v4.0: BAJA
Última modificación:
21/09/2026

CVE-2026-93988

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email parameter to bypass directory restrictions and access sensitive files including database credentials and configuration data.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/10/2026

CVE-2026-93954

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of the component Settings API Endpoint. Such manipulation leads to incorrect authorization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 2b66ca6df8110f6b512e030b54c16b9fbe318f17. Applying a patch is advised to resolve this issue. PR #2558, merged as 53abc8b, moved the OIDC secret into a dedicated setting, but did not by itself restrict GET /api/v1/settings.
Gravedad CVSS v4.0: BAJA
Última modificación:
22/09/2026