Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-6396

Publication date:
12/07/2024
A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfiltrate arbitrary data. The vulnerability arises due to improper handling of the `run_hash` and `repo.path` parameters, which can be manipulated to create and write to arbitrary file paths. This can lead to denial of service by overwriting critical system files, loss of private data, and potential remote code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2025

CVE-2024-6392

Publication date:
11/07/2024
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modification due to missing capability checks on the plugin functions in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the connected Sirv account to an attacker-controlled one.
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2026

CVE-2024-36435

Publication date:
11/07/2024
An issue was discovered on Supermicro BMC firmware in select X11, X12, H12, B12, X13, H13, and B13 motherboards (and CMM6 modules). An unauthenticated user can post crafted data to the interface that triggers a stack buffer overflow, and may lead to arbitrary remote code execution on a BMC.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2024-6468

Publication date:
11/07/2024
Vault and Vault Enterprise did not properly handle requests originating from unauthorized IP addresses when the TCP listener option, proxy_protocol_behavior, was set to deny_unauthorized. When receiving a request from a source IP address that was not listed in proxy_protocol_authorized_addrs, the Vault API server would shut down and no longer respond to any HTTP requests, potentially resulting in denial of service.<br /> <br /> While this bug also affected versions of Vault up to 1.17.1 and 1.16.5, a separate regression in those release series did not allow Vault operators to configure the deny_unauthorized option, thus not allowing the conditions for the denial of service to occur.<br /> <br /> Fixed in Vault and Vault Enterprise 1.17.2, 1.16.6, and 1.15.12.
Severity CVSS v4.0: Pending analysis
Last modification:
13/08/2025

CVE-2022-29946

Publication date:
11/07/2024
NATS.io NATS Server before 2.8.2 and Streaming Server before 0.24.6 could allow a remote attacker to bypass security restrictions, caused by the failure to enforce negative user permissions in one scenario. By using a queue subscription on the wildcard, an attacker could exploit this vulnerability to allow denied subjects.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2024-6531

Publication date:
11/07/2024
Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the reported behavior fell outside the scope of Bootstrap’s security model, and the associated CVE has been rescinded.
Severity CVSS v4.0: Pending analysis
Last modification:
01/08/2025

CVE-2024-6484

Publication date:
11/07/2024
Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the reported behavior fell outside the scope of Bootstrap’s security model, and the associated CVE has been rescinded.
Severity CVSS v4.0: Pending analysis
Last modification:
01/08/2025

CVE-2024-6485

Publication date:
11/07/2024
A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button&amp;#39;s loading state is triggered.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2024-6681

Publication date:
11/07/2024
A vulnerability, which was classified as critical, has been found in witmy my-springsecurity-plus up to 2024-07-04. Affected by this issue is some unknown functionality of the file /api/dept. The manipulation of the argument params.dataScope leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-271154 is the identifier assigned to this vulnerability.
Severity CVSS v4.0: MEDIUM
Last modification:
10/10/2025

CVE-2024-39552

Publication date:
11/07/2024
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a network based, unauthenticated attacker to cause the RPD process to crash leading to a Denial of Service (DoS).<br /> <br /> When a malformed BGP UPDATE packet is received over an established BGP session, RPD crashes and restarts.<br /> <br /> Continuous receipt of the malformed BGP UPDATE messages will create a sustained Denial of Service (DoS) condition for impacted devices.<br /> <br /> This issue affects eBGP and iBGP, in both IPv4 and IPv6 implementations. This issue requires a remote attacker to have at least one established BGP session.<br /> <br /> This issue affects:<br /> <br /> Juniper Networks Junos OS:<br /> * All versions earlier than 20.4R3-S9;<br /> * 21.2 versions earlier than 21.2R3-S7;<br /> * 21.3 versions earlier than 21.3R3-S5;<br /> * 21.4 versions earlier than 21.4R3-S6;<br /> * 22.1 versions earlier than 22.1R3-S4;<br /> * 22.2 versions earlier than 22.2R3-S3;<br /> * 22.3 versions earlier than 22.3R3-S2;<br /> * 22.4 versions earlier than 22.4R3;<br /> * 23.2 versions earlier than 23.2R2.<br /> <br /> <br /> <br /> Juniper Networks Junos OS Evolved:<br /> * All versions earlier than 21.2R3-S7;<br /> * 21.3-EVO versions earlier than 21.3R3-S5;<br /> * 21.4-EVO versions earlier than 21.4R3-S8;<br /> * 22.1-EVO versions earlier than 22.1R3-S4;<br /> * 22.2-EVO versions earlier than 22.2R3-S3;<br /> * 22.3-EVO versions earlier than 22.3R3-S2;<br /> * 22.4-EVO versions earlier than 22.4R3;<br /> * 23.2-EVO versions earlier than 23.2R2.
Severity CVSS v4.0: HIGH
Last modification:
23/01/2026

CVE-2024-39553

Publication date:
11/07/2024
An Exposure of Resource to Wrong Sphere vulnerability in the sampling service of Juniper Networks Junos OS Evolved allows an unauthenticated network-based attacker to send arbitrary data to the device, which leads msvcsd process to crash with limited availability impacting Denial of Service (DoS) and allows unauthorized network access to the device, potentially impacting system integrity.<br /> <br /> This issue only happens when inline jflow is configured.<br /> <br /> This does not impact any forwarding traffic. The impacted services MSVCS-DB app crashes momentarily and recovers by itself. <br /> <br /> This issue affects Juniper Networks Junos OS Evolved: <br /> * 21.4 versions earlier than 21.4R3-S7-EVO; <br /> * 22.2 versions earlier than 22.2R3-S3-EVO;<br /> * 22.3 versions earlier than 22.3R3-S2-EVO;<br /> * 22.4 versions earlier than 22.4R3-EVO;<br /> * 23.2 versions earlier than 23.2R1-S2-EVO, 23.2R2-EVO.
Severity CVSS v4.0: MEDIUM
Last modification:
23/01/2026

CVE-2024-39551

Publication date:
11/07/2024
An Uncontrolled Resource Consumption vulnerability in the H.323 ALG (Application Layer Gateway) of  Juniper Networks Junos OS on SRX Series and MX Series with SPC3 and MS-MPC/MIC, allows an unauthenticated network-based attacker to send specific packets causing traffic loss leading to Denial of Service (DoS). <br /> <br /> Continued receipt and processing of these specific packets will sustain the Denial of Service condition.<br /> <br /> The memory usage can be monitored using the below command.<br /> <br />   user@host&gt; show usp memory segment sha data objcache jsf <br /> This issue affects SRX Series and MX Series with SPC3 and MS-MPC/MIC: <br /> <br /> *  20.4 before 20.4R3-S10, <br /> *  21.2 before 21.2R3-S6, <br /> *  21.3 before 21.3R3-S5, <br /> *  21.4 before 21.4R3-S6, <br /> *  22.1 before 22.1R3-S4, <br /> *  22.2 before 22.2R3-S2, <br /> *  22.3 before 22.3R3-S1, <br /> *  22.4 before 22.4R3, <br /> *  23.2 before 23.2R2.
Severity CVSS v4.0: HIGH
Last modification:
23/01/2026