Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2019-25743

Fecha de publicación:
04/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting script tags in the post title field. Attackers can submit POST requests to the post editing endpoint with script payloads in the post_title parameter, which are stored and executed when users preview the post.
Gravedad CVSS v4.0: MEDIA
Última modificación:
17/06/2026

CVE-2019-25744

Fecha de publicación:
04/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by breaking out of option tags in the post_title parameter. Attackers can submit crafted POST requests to the post.php endpoint with script payloads in the post_title field that execute when pages or posts display popup selections.
Gravedad CVSS v4.0: MEDIA
Última modificación:
17/06/2026

CVE-2019-25745

Fecha de publicación:
04/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** WordPress Plugin Google Review Slider 6.1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'tid' parameter. Attackers can send GET requests to the admin interface with malicious 'tid' values to extract sensitive database information using time-based blind SQL injection techniques.
Gravedad CVSS v4.0: ALTA
Última modificación:
17/06/2026

CVE-2019-25737

Fecha de publicación:
04/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Live Chat Unlimited 2.8.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the chat input field. Attackers can submit payloads containing script tags and event handlers that execute in the admin area, enabling cookie theft or forced redirects to malicious websites.
Gravedad CVSS v4.0: MEDIA
Última modificación:
17/06/2026

CVE-2019-25738

Fecha de publicación:
04/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option action. Attackers can send POST requests to the admin-ajax.php endpoint with the action parameter set to hc_ajax_save_option to enable user registration and set the default role to administrator, enabling account takeover.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
17/06/2026

CVE-2019-25739

Fecha de publicación:
04/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** GigToDo 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript and HTML code through the proposal description field. Attackers can craft XSS payloads in the create_proposal endpoint that execute when administrators or other users view the stored proposal, enabling cookie theft and malicious redirects.
Gravedad CVSS v4.0: MEDIA
Última modificación:
17/06/2026

CVE-2019-25740

Fecha de publicación:
04/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom userfield parameters. Attackers can send POST requests to the job.savejob task with path traversal sequences in the field_2 parameter to delete arbitrary files accessible to the web server.
Gravedad CVSS v4.0: ALTA
Última modificación:
17/06/2026

CVE-2019-25741

Fecha de publicación:
04/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the username field of session files that allows remote attackers to execute arbitrary code. Attackers can craft a malicious MobaXterm sessions file with overflow data that triggers the vulnerability when imported and executed, enabling reverse shell execution with user privileges.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
17/06/2026

CVE-2019-25731

Fecha de publicación:
04/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Zuz Music 2.1 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious JavaScript by submitting crafted contact form data. Attackers can inject script code through the name, subject, and message parameters in POST requests to /gmusic/zuzconsole/___contact, which executes when administrators view messages in the inbox interface.
Gravedad CVSS v4.0: MEDIA
Última modificación:
17/06/2026

CVE-2019-25732

Fecha de publicación:
04/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** PHP EI-Tube Script 3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can send GET requests to the search endpoint with crafted SQL payloads in the query parameter to extract sensitive database information including usernames, passwords, and version details.
Gravedad CVSS v4.0: ALTA
Última modificación:
17/06/2026

CVE-2019-25733

Fecha de publicación:
04/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** NetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input. Attackers can craft a payload with overwritten SEH and NSEH pointers through the Restrictions custom filter field to trigger code execution when the Find function is invoked.
Gravedad CVSS v4.0: ALTA
Última modificación:
17/06/2026

CVE-2019-25734

Fecha de publicación:
04/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that allows unauthenticated attackers to include arbitrary files by exploiting unsanitized action parameters. Attackers can craft malicious forms targeting the admin-ajax.php endpoint with directory traversal sequences in the GET action parameter to load files via CSRF, bypassing authentication on vulnerable AJAX actions.
Gravedad CVSS v4.0: MEDIA
Última modificación:
17/06/2026