Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-90557

Fecha de publicación:
12/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an out-of-range activity index that bypasses bounds checking and causes a crash or limited heap memory exposure when loaded.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/09/2026

CVE-2026-90559

Fecha de publicación:
12/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size. Attackers can supply valid compressed data that decompresses larger than the destination buffer, causing writes past buffer boundaries and JVM termination.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/10/2026

CVE-2026-90554

Fecha de publicación:
12/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** vLLM versions >=0.10.2 and
Gravedad CVSS v4.0: MEDIA
Última modificación:
24/09/2026

CVE-2026-90551

Fecha de publicación:
12/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_from_program API endpoint, allowing unauthenticated access to private playlist contents. Attackers can query the API without authentication to enumerate private playlist names, owner information, and video titles including password-protected content.
Gravedad CVSS v4.0: MEDIA
Última modificación:
21/09/2026

CVE-2026-90546

Fecha de publicación:
12/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the like.json.php endpoint, allowing logged-in users to record likes on password-protected and group-restricted videos. Attackers can submit like requests for videos they cannot watch to increment like counters and bypass access controls.
Gravedad CVSS v4.0: MEDIA
Última modificación:
21/09/2026

CVE-2026-90536

Fecha de publicación:
12/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoint, allowing unauthenticated attackers to retrieve password-protected video owner identifiers. Attackers can call the adsInfo API with a videos_id parameter to obtain the owner's user ID and personalized ad creative URLs without authentication or permission checks.
Gravedad CVSS v4.0: MEDIA
Última modificación:
21/09/2026

CVE-2026-90472

Fecha de publicación:
12/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and trigger StackOverflowError, causing per-request deserialization failures.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/09/2026

CVE-2026-90473

Fecha de publicación:
12/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element count at or above 0x40000000 that wraps when doubled, causing the parser cursor to desynchronize and attacker-controlled data to be returned in place of later fields.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/09/2026

CVE-2026-90474

Fecha de publicación:
12/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** MCPHub before 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server where client authentication is disabled by default and PKCE enforcement is optional. Attackers who obtain an authorization code through interception can redeem it for access tokens without providing a client secret or PKCE verifier, gaining access to victim accounts and their privileges.
Gravedad CVSS v4.0: ALTA
Última modificación:
23/09/2026

CVE-2026-77006

Fecha de publicación:
12/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WebTotem Backups WordPress plugin before 1.1.0 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
23/09/2026

CVE-2026-87719

Fecha de publicación:
12/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
28/09/2026

CVE-2026-85706

Fecha de publicación:
12/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
24/09/2026