Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-90467

Fecha de publicación:
12/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and angle brackets to append parameters like AUTH, NOTIFY, or ORCPT to envelope commands, forging authenticated identities or forcing delivery notifications to third parties.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/09/2026

CVE-2026-89268

Fecha de publicación:
12/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim's session to read administrative data and perform actions.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/09/2026

CVE-2026-89267

Fecha de publicación:
12/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to perform equality and comparison operations on excluded columns.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/09/2026

CVE-2026-89266

Fecha de publicación:
12/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes, causing process crashes or heap corruption.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/09/2026

CVE-2026-90460

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or deleting credentials via the /v3/credentials API. EC2-derived tokens can additionally read credential blobs, exposing TOTP MFA seeds and other secrets. Also, PATCH /v3/credentials does not validate the requested post-update project_id, allowing any delegated token to move a credential to an unauthorized project. All Keystone deployments using delegated authentication are affected.
Gravedad CVSS v4.0: ALTA
Última modificación:
22/09/2026

CVE-2026-90457

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash is written with permissions allowing it to be read by any local user. This is inconsistent with a separate, stronger hashing algorithm used for the same password on another authentication path. A party able to read this file, including a local user or a party with access to a configuration backup, could feasibly recover the underlying password through offline computation, compromising the administrative credential across every path that accepts it.
Gravedad CVSS v4.0: MEDIA
Última modificación:
02/10/2026

CVE-2026-90461

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/10/2026

CVE-2026-90452

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker positioned on the network path between the proxy and the identity provider could impersonate the identity provider and issue forged authentication tokens accepted by the deployment.
Gravedad CVSS v4.0: MEDIA
Última modificación:
02/10/2026

CVE-2026-90453

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. This allows an authenticated attacker to craft a request that causes another user's browser to be redirected to an arbitrary external destination after completing an upload.
Gravedad CVSS v4.0: MEDIA
Última modificación:
02/10/2026

CVE-2026-90454

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tags attached to stored session records, and the proxy configuration otherwise permits the request method those routes use. This allows an authenticated user on a deployment intended to be read-only to add or remove tags on stored session records.
Gravedad CVSS v4.0: MEDIA
Última modificación:
02/10/2026

CVE-2026-90455

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a single fixed, trusted vendor URL at initialization and does not process attacker-controlled input through the library, limiting practical exploitability of the reintroduced version in this context.
Gravedad CVSS v4.0: MEDIA
Última modificación:
02/10/2026

CVE-2026-90456

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
02/10/2026