Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-24792

Publication date:
27/06/2024
Parsing a corrupt or malicious image with invalid color indices can cause a panic.
Severity CVSS v4.0: Pending analysis
Last modification:
01/08/2024

CVE-2023-38371

Publication date:
27/06/2024
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 261198.
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2025

CVE-2024-39669

Publication date:
27/06/2024
In the Console in Soffid IAM before 3.5.39, necessary checks were not applied to some Java objects. A malicious agent could possibly execute arbitrary code in the Sync Server and compromise security.
Severity CVSS v4.0: Pending analysis
Last modification:
03/07/2024

CVE-2024-6388

Publication date:
27/06/2024
Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2025

CVE-2024-31883

Publication date:
27/06/2024
IBM Security Verify Access 10.0.0.0 through 10.0.7.1, under certain configurations, could allow an unauthenticated attacker to cause a denial of service due to asymmetric resource consumption. IBM X-Force ID: 287615.
Severity CVSS v4.0: Pending analysis
Last modification:
02/08/2024

CVE-2024-39373

Publication date:
27/06/2024
TELSAT marKoni FM Transmitters are vulnerable to a command injection vulnerability through the manipulation of settings and could allow an attacker to gain unauthorized access to the system with administrative privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
17/09/2024

CVE-2024-39374

Publication date:
27/06/2024
TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed through the use of hard-coded credentials.
Severity CVSS v4.0: Pending analysis
Last modification:
17/09/2024

CVE-2024-39375

Publication date:
27/06/2024
TELSAT marKoni FM Transmitters are vulnerable to an attacker bypassing authentication and gaining administrator privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
17/09/2024

CVE-2024-39376

Publication date:
27/06/2024
TELSAT marKoni FM Transmitters are vulnerable to users gaining unauthorized access to sensitive information or performing actions beyond their designated permissions.
Severity CVSS v4.0: Pending analysis
Last modification:
17/09/2024

CVE-2023-30430

Publication date:
27/06/2024
IBM Security Verify Access 10.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from trace logs. IBM X-Force ID: 252183.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2024

CVE-2024-28820

Publication date:
27/06/2024
Buffer overflow in the extract_openvpn_cr function in openvpn-cr.c in openvpn-auth-ldap (aka the Three Rings Auth-LDAP plugin for OpenVPN) 2.0.4 allows attackers with a valid LDAP username and who can control the challenge/response password field to pass a string with more than 14 colons into this field and cause a buffer overflow.
Severity CVSS v4.0: Pending analysis
Last modification:
04/11/2024

CVE-2024-6374

Publication date:
27/06/2024
A vulnerability was found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as problematic. This issue affects some unknown processing of the file /subject.php of the component Subject Page. The manipulation of the argument Subject Title/Sybillus Details leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269807.
Severity CVSS v4.0: Pending analysis
Last modification:
27/06/2024