Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-39250

Publication date:
22/07/2024
EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in the search web interface.
Severity CVSS v4.0: Pending analysis
Last modification:
08/07/2025

CVE-2024-6121

Publication date:
22/07/2024
An out-of-date version of Redis shipped with NI SystemLink Server is susceptible to multiple vulnerabilities, including CVE-2022-24834. This affects NI SystemLink Server 2024 Q1 and prior versions. It also affects NI FlexLogger 2023 Q2 and prior versions which installed this shared service.
Severity CVSS v4.0: Pending analysis
Last modification:
12/09/2024

CVE-2024-6122

Publication date:
22/07/2024
An incorrect permission in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may result in information disclosure via local access. This affects NI SystemLink Server 2024 Q1 and prior versions. It also affects NI FlexLogger 2023 Q2 and prior versions which installed this shared service.
Severity CVSS v4.0: Pending analysis
Last modification:
10/09/2024

CVE-2024-6638

Publication date:
22/07/2024
An integer overflow vulnerability due to improper input validation when reading TDMS files in LabVIEW may result in an infinite loop. Successful exploitation requires an attacker to provide a user with a specially crafted TDMS file. This vulnerability affects LabVIEW 2024 Q1 and prior versions.
Severity CVSS v4.0: Pending analysis
Last modification:
06/03/2025

CVE-2024-34329

Publication date:
22/07/2024
Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch allows unauthenticated attackers to execute arbitrary code as SYSTEM via a crafted DLL payload.
Severity CVSS v4.0: Pending analysis
Last modification:
14/03/2025

CVE-2024-37380

Publication date:
22/07/2024
A misconfiguration on UniFi U6+ Access Point could cause an incorrect VLAN traffic forwarding to APs meshed to UniFi U6+ Access Point.<br /> <br /> <br /> Affected Products:<br /> UniFi U6+ Access Point (Version 6.6.65 and earlier) <br /> <br /> <br /> Mitigation:<br /> Update your UniFi U6+ Access Point to Version 6.6.74 or later.<br />
Severity CVSS v4.0: Pending analysis
Last modification:
24/07/2024

CVE-2024-38944

Publication date:
22/07/2024
An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the /cgi-bin/generateForm.cgi?formID=142 component.
Severity CVSS v4.0: Pending analysis
Last modification:
01/08/2024

CVE-2024-40075

Publication date:
22/07/2024
Laravel v11.x was discovered to contain an XML External Entity (XXE) vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
02/12/2024

CVE-2024-41880

Publication date:
22/07/2024
In veilid-core in Veilid before 0.3.4, the protocol&amp;#39;s ping function can be misused in a way that decreases the effectiveness of safety and private routes.
Severity CVSS v4.0: Pending analysis
Last modification:
01/08/2024

CVE-2024-41130

Publication date:
22/07/2024
llama.cpp provides LLM inference in C/C++. Prior to b3427, llama.cpp contains a null pointer dereference in gguf_init_from_file. This vulnerability is fixed in b3427.
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2025

CVE-2024-28698

Publication date:
22/07/2024
Directory Traversal vulnerability in Marimer LLC CSLA .Net before 8.0 allows a remote attacker to execute arbitrary code via a crafted script to the MobileFormatter component.
Severity CVSS v4.0: Pending analysis
Last modification:
01/08/2024

CVE-2024-40051

Publication date:
22/07/2024
IP Guard v4.81.0307.0 was discovered to contain an arbitrary file read vulnerability via the file name parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
16/08/2024