Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-93504

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+server.ts of the component User Attribute Update Endpoint. Such manipulation leads to improper access controls. It is possible to launch the attack remotely. The name of the patch is 05b4f9efeb79e9d72a693232334d7529687f896f. It is advisable to implement a patch to correct this issue.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/09/2026

CVE-2026-93018

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p.<br /> <br /> The palette is allocated uninitialised, and only the entries a reader adds count as populated. The TGA reader stores pixel indexes without checking them against the colour map. i_gpix_p() rejects only an index greater than the count, so an index equal to it reads the first unpopulated entry, and getpixel() returns it.<br /> <br /> i_glin_p() skips any index at or beyond the count without writing that pixel to the caller&amp;#39;s buffer. The palette-to-RGB conversion reads each row through an uninitialised buffer, so those pixels of the converted image hold prior heap contents.<br /> <br /> Reading an attacker-supplied image through Imager-&gt;read() and then fetching its pixels or converting it to RGB discloses process heap memory.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/09/2026

CVE-2026-88623

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the user via POST is received, and fopen() is used to open the URL in binary read-only mode. The content is then written to the /tmp/ directory, with the filename derived from basename() of the URL. This operation requires no authentication.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-88622

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-79294

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbitrary code via the HTML artifact Preview rendering; public Share view component
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/09/2026

CVE-2026-62282

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack integrations does not sufficiently validate user-supplied HTTP or HTTPS destinations. An authenticated user with permission to configure notification channels can trigger requests to hosts reachable from the OpenCVE server, including internal network resources, localhost interfaces, link-local addresses, and cloud metadata services, and retrieve information from reachable HTTP services. This issue is fixed in version 3.0.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/09/2026

CVE-2026-93491

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in Netty&amp;#39;s HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without limit, leading to unbounded heap memory consumption and a denial of service due to memory exhaustion.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-93492

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in Netty&amp;#39;s HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large MAX_HEADER_TABLE_SIZE. This causes the HpackEncoder to store an excessive number of unique headers, leading to increased CPU usage and memory consumption, ultimately resulting in a Denial of Service (DoS).
Gravedad CVSS v3.1: MEDIA
Última modificación:
29/09/2026

CVE-2026-93488

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no API to change it. A remote peer can open a SPDY connection and send a large number of SYN_STREAM frames with FLAG_FIN=0, causing unbounded heap and direct memory allocation that can lead to JVM OutOfMemoryError and a denial of service.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-93575

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in Netty&amp;#39;s MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted MQTT CONNECT packet. The decoder fails to properly validate the &amp;#39;Properties Length&amp;#39; against the &amp;#39;Remaining Length&amp;#39;, allowing an attacker to bypass size limits. This leads to excessive memory and CPU consumption, resulting in a denial of service (DoS) due to an OutOfMemoryError.
Gravedad CVSS v3.1: ALTA
Última modificación:
25/09/2026

CVE-2026-93561

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types instead of unsigned, as specified by the protocol. A malicious Memcache server can exploit this type mismatch by sending a specially crafted response. This can lead to frame desynchronization and response smuggling, where one client&amp;#39;s data may be inadvertently exposed to another client&amp;#39;s response stream in proxy or cache environments.
Gravedad CVSS v3.1: MEDIA
Última modificación:
25/09/2026

CVE-2026-93563

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in Netty&amp;#39;s `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-middle (MITM) SMTP server, could exploit this by sending a specially crafted, unbounded multi-line SMTP response without a terminator. This vulnerability leads to unbounded memory accumulation within the client&amp;#39;s Java Virtual Machine (JVM) heap, causing an `OutOfMemoryError` and a denial of service (DoS) due to a process crash.
Gravedad CVSS v3.1: ALTA
Última modificación:
25/09/2026