Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-29347

Publication date:
11/07/2023
Windows Admin Center Spoofing Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
29/05/2024

CVE-2023-21756

Publication date:
11/07/2023
Windows Win32k Elevation of Privilege Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
29/05/2024

CVE-2023-21526

Publication date:
11/07/2023
Windows Netlogon Information Disclosure Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
13/07/2023

CVE-2023-32039

Publication date:
11/07/2023
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
29/05/2024

CVE-2023-32040

Publication date:
11/07/2023
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
29/05/2024

CVE-2023-3354

Publication date:
11/07/2023
A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
11/03/2024

CVE-2023-37597

Publication date:
11/07/2023
Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delete user grouplist function.
Severity CVSS v4.0: Pending analysis
Last modification:
18/07/2023

CVE-2023-3627

Publication date:
11/07/2023
Cross-Site Request Forgery (CSRF) in GitHub repository salesagility/suitecrm-core prior to 8.3.1.
Severity CVSS v4.0: Pending analysis
Last modification:
18/07/2023

CVE-2023-37596

Publication date:
11/07/2023
Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via a crafted script to the deleteuser function.
Severity CVSS v4.0: Pending analysis
Last modification:
18/07/2023

CVE-2023-34116

Publication date:
11/07/2023
Improper input validation in the Zoom Desktop Client for Windows before version 5.15.0 may allow an unauthorized user to enable an escalation of privilege via network access.
Severity CVSS v4.0: Pending analysis
Last modification:
19/09/2024

CVE-2023-34117

Publication date:
11/07/2023
Relative path traversal in the Zoom Client SDK before version 5.15.0 may allow an unauthorized user to enable information disclosure via local access.
Severity CVSS v4.0: Pending analysis
Last modification:
19/09/2024

CVE-2023-3624

Publication date:
11/07/2023
A vulnerability classified as critical has been found in Nesote Inout Blockchain FiatExchanger 3.0. This affects an unknown part of the file /index.php/coins/update_marketboxslider of the component POST Parameter Handler. The manipulation of the argument marketcurrency leads to sql injection. It is possible to initiate the attack remotely. The identifier VDB-233577 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity CVSS v4.0: Pending analysis
Last modification:
17/05/2024