Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-25294

Fecha de publicación:
17/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Transient DOS while parsing frame during channel usage.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-24075

Fecha de publicación:
17/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-25275

Fecha de publicación:
17/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Transient DOS when processing authentication frames with invalid FILS information element header lengths.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-25280

Fecha de publicación:
17/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Memory corruption when processing escape handling flow with insufficient user buffer sizes.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-25278

Fecha de publicación:
17/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-25261

Fecha de publicación:
17/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Memory corruption while processing rear sensor IOCTL calls.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/09/2026

CVE-2026-24081

Fecha de publicación:
17/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-24074

Fecha de publicación:
17/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-24073

Fecha de publicación:
17/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2025-59607

Fecha de publicación:
17/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Memory Corruption when copying large input data exceeds normal allocation limits.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-61599

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the djust live transport resolves the LiveView to mount from a client-supplied dotted path by calling `__import__(module_path, ...)`. The module is imported — running its top-level code (import side effects) — before the framework checks that the resolved object is a `LiveView` subclass and before any per-view authentication. The `LIVEVIEW_ALLOWED_MODULES` allowlist that should contain this is fail-open (`if allowed_modules:` — skipped when the setting is unset, the framework default) and uses loose `startswith` matching. An unauthenticated WebSocket client (the WS handshake does not require auth; per-view auth runs only after import + instantiate) can therefore send a `mount` / `live_redirect_mount` / `url_change` frame (or an SSE mount) with `view = ".AnyName"` and cause the server to import — and execute the top-level code of — any importable Python module by name. Version 1.0.7 fixes the issue with a fail-closed resolution gate (`djust._view_resolution.is_view_import_allowed`): a client view path resolves only if (a) its module is already loaded (`sys.modules` — so resolving runs no new code; URL-routed views loaded by URLconf at startup keep working with zero config) or (b) it matches `LIVEVIEW_ALLOWED_MODULES` on a module-segment boundary (explicit opt-in for lazily-imported views). The gate runs before `__import__` at all three sinks (+ defense-in-depth inside `_instantiate_view`). As a workaround, set `LIVEVIEW_ALLOWED_MODULES` to the narrow list of modules that contain your mountable LiveView classes. (Note: pre-patch the allowlist is `startswith`-matched and the import still precedes the subclass check, so this is mitigation, not a complete fix.)
Gravedad CVSS v4.0: ALTA
Última modificación:
30/09/2026

CVE-2026-61589

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the WebSocket `handle_mount` and `ViewRuntime._build_request` rebuild an `HttpRequest` via `RequestFactory().get(...)` with no `HTTP_HOST`, so `request.get_host()` defaulted to `"testserver"` on the live path. Host/subdomain/domain `TenantResolver`s then misresolved the tenant — `None` on the live path while the HTTP path resolved correctly. With `STRICT_MODE=False` the tenant-scoped managers returned unscoped rows (cross-tenant disclosure); with the default they returned an empty queryset (broken tenancy). This is fixed in djust 1.0.7. The handshake Host is extracted from the ASGI scope, validated against `ALLOWED_HOSTS` (the same logic as the CSWSH Origin gate, parsed with Django's `split_domain_port` so malformed Hosts are rejected at the boundary), and propagated — with the TLS scheme — into the reconstructed request, so live-path tenant resolution matches HTTP exactly. There is no known workaround on the live path short of upgrading. Users are most exposed when combined with `STRICT_MODE=False`.
Gravedad CVSS v3.1: MEDIA
Última modificación:
30/09/2026