Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-45719

Publication date:
22/11/2024
Inadequate Encryption Strength vulnerability in Apache Answer.<br /> <br /> This issue affects Apache Answer: through 1.4.0.<br /> <br /> The ids generated using the UUID v1 version are to some extent not secure enough. It can cause the generated token to be predictable.<br /> Users are recommended to upgrade to version 1.4.1, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
01/07/2025

CVE-2024-41781

Publication date:
22/11/2024
IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1030.00 through FW1030.60, FW1050.00 through FW1050.20, and FW1060.00 through FW1060.10 functionality can be compromised if an attacker gains service access to the HMC. An attacker that gains service access to the HMC can locate and through a series of service procedures decrypt data contained in the Platform KeyStore.
Severity CVSS v4.0: Pending analysis
Last modification:
15/08/2025

CVE-2024-51766

Publication date:
22/11/2024
A potential security vulnerability has been identified in the HPE NonStop DISK UTIL (T9208) product. This vulnerability could be exploited to cause a denial of service (DoS) to NonStop server. It exists in all prior DISK UTIL product versions of L-series and J-series.
Severity CVSS v4.0: Pending analysis
Last modification:
22/11/2024

CVE-2024-41779

Publication date:
22/11/2024
IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vulnerability to remotely execute code.
Severity CVSS v4.0: Pending analysis
Last modification:
15/08/2025

CVE-2021-30299

Publication date:
22/11/2024
Possible out of bound access in audio module due to lack of validation of user provided input.
Severity CVSS v4.0: Pending analysis
Last modification:
25/11/2024

CVE-2017-9711

Publication date:
22/11/2024
Certain unprivileged processes are able to perform IOCTL calls.
Severity CVSS v4.0: Pending analysis
Last modification:
25/11/2024

CVE-2024-7882

Publication date:
22/11/2024
Improper Neutralization of Special Elements used in an SQL Command (&amp;#39;SQL Injection&amp;#39;) vulnerability in Special Minds Design and Software e-Commerce allows SQL Injection.This issue affects e-Commerce: before 22.11.2024.
Severity CVSS v4.0: Pending analysis
Last modification:
26/11/2024

CVE-2024-7837

Publication date:
22/11/2024
Improper Neutralization of Special Elements used in an SQL Command (&amp;#39;SQL Injection&amp;#39;) vulnerability in Firmanet Software ERP allows SQL Injection.This issue affects ERP: through 22.11.2024.<br /> <br /> <br /> NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity CVSS v4.0: Pending analysis
Last modification:
22/11/2024

CVE-2024-8929

Publication date:
22/11/2024
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2025

CVE-2024-8735

Publication date:
22/11/2024
The MailMunch – Grow your Email List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.1.8. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Severity CVSS v4.0: Pending analysis
Last modification:
11/02/2025

CVE-2024-9422

Publication date:
22/11/2024
The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.
Severity CVSS v4.0: Pending analysis
Last modification:
09/06/2025

CVE-2024-8932

Publication date:
22/11/2024
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2025