Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-71646

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause a denial of service via the FastExplorationFSM::optTimerCallback() in swarm_exploration/exploration_manager/src/fast_exploration_fsm.cpp
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-79362

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until = 6.2.0 until
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-54072

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` or `response_type=id_token`, the server appends `access_token`, `id_token`, and `refresh_token` as query parameters and issues a 302 redirect to the attacker-supplied URL. An unauthenticated attacker can obtain the required `client_id` from the public `/graphql?query={meta{client_id}}` endpoint. A partial fix was applied in v2.0.1 to other handlers (`oauth_login`, `verify_email`, `magic_link_login`, `forgot_password`, `invite_members`, `oauth_callback`) but `/authorize` was not included. Version 2.2.1 contains a more complete fix.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
30/09/2026

CVE-2025-69904

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on the server by manipulating file path input. Successful exploitation may lead to unauthorized access to sensitive system or application files.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/09/2026

CVE-2026-89099

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user holding ordinary read-write privileges on a database may be able to trigger this condition over the normal client protocol, resulting in server termination and potential corruption of process memory with user-influenced content. Successful use of this issue may impact the confidentiality, integrity, and availability of the affected server process.
Gravedad CVSS v4.0: ALTA
Última modificación:
29/09/2026

CVE-2026-82535

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Chamilo LMS before 1.11.42 and 3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious script payloads into survey answers by computing deterministic invitation codes and bypassing authorization checks in the survey submission endpoint. Attackers can submit crafted answers containing unescaped HTML rendered in reporting views to execute arbitrary scripts in the browser sessions of teachers or administrators, enabling persistent backdoor account creation by exploiting the victim's authenticated session.
Gravedad CVSS v4.0: MEDIA
Última modificación:
24/09/2026

CVE-2026-87910

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None.
Gravedad CVSS v4.0: MEDIA
Última modificación:
03/10/2026

CVE-2026-7298

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper neutralization of input during web page generation (&amp;#39;cross-site scripting&amp;#39;) vulnerability in IdeaSoft Software Industry and Trade Inc. Smart E-Commerce allows Reflected XSS.<br /> <br /> This issue affects Smart E-Commerce: before 8.4.2.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
25/09/2026

CVE-2026-78807

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-18495

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/10/2026

CVE-2026-54047

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior to 1.2.3 have an improper authentication vulnerability in the application&amp;#39;s OAuth2 login flow. The application relies on client-side state by trusting the `UID` field inside the `Authentications` object of a user&amp;#39;s local `config.json` file. By manually editing this local file on their PC prior to logging in, a user can supply an arbitrary UID. Because the server fails to validate that the authenticated OAuth2 identity matches the requested UID, an attacker can fully impersonate any target user and perform actions on their behalf. This issue has been resolved in version 1.2.3. The patch modifies `AuthorizeOauthAsync` inside the `SecretKeyAuthenticatorService` to strictly bind the lookup of the requested User ID (`requestedUid`) to the record of the successfully authenticated identity (`primaryUid`). The server will no longer load or return session tokens for a requested UID unless it matches the verified, authenticated database record. No known workarounds are available.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
30/09/2026

CVE-2026-89012

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by supplying uppercase variants of denylist-protected field names. Attackers can exploit the case-insensitive database column resolution against the case-sensitive denylist check in the core library to use prefix-matching predicates as a boolean oracle and extract full password hashes for any user account, including administrators.
Gravedad CVSS v4.0: ALTA
Última modificación:
23/09/2026