Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-90781

Fecha de publicación:
13/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.
Gravedad CVSS v4.0: MEDIA
Última modificación:
24/09/2026

CVE-2026-90782

Fecha de publicación:
13/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() where a failed allocation for DataChangeNotification is overwritten by a successful allocation for EventNotificationList. Attackers can trigger heap allocation failures on sessions with both data-change and event notifications to cause the server process to terminate.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/09/2026

CVE-2026-90783

Fecha de publicación:
13/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/09/2026

CVE-2026-90520

Fecha de publicación:
13/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization Interceptor. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of the patch is d984d172dceca907f8b447efbdb06dc233f7938d. Applying a patch is the recommended action to fix this issue.
Gravedad CVSS v4.0: BAJA
Última modificación:
20/09/2026

CVE-2026-90780

Fecha de publicación:
13/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP messages with oversized headers to overflow the static buffer and crash the process.
Gravedad CVSS v4.0: ALTA
Última modificación:
23/09/2026

CVE-2026-90776

Fecha de publicación:
13/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to consume excessive CPU and block the Node.js event loop for several seconds, causing denial of service.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/09/2026

CVE-2026-90775

Fecha de publicación:
13/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out-of-bounds reads in the load_value array, causing the PostgreSQL backend process to crash and terminate all cluster sessions.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/09/2026

CVE-2026-90777

Fecha de publicación:
13/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code during deserialization when loaded through the initialization or fine-tuning path.
Gravedad CVSS v4.0: ALTA
Última modificación:
23/09/2026

CVE-2026-90779

Fecha de publicación:
13/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt the stack and crash the client process.
Gravedad CVSS v4.0: ALTA
Última modificación:
23/09/2026

CVE-2026-90778

Fecha de publicación:
13/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag parameters to overflow the static buffer and crash the process.
Gravedad CVSS v4.0: ALTA
Última modificación:
23/09/2026

CVE-2026-90515

Fecha de publicación:
13/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknown function of the file /bilal/normal/delete_stud.php. Executing a manipulation of the argument selector[] can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Gravedad CVSS v4.0: MEDIA
Última modificación:
20/09/2026

CVE-2026-90774

Fecha de publicación:
13/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write files outside the configured upload directory to arbitrary locations.
Gravedad CVSS v4.0: ALTA
Última modificación:
23/09/2026