Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-28833

Publication date:
10/06/2024
Improper restriction of excessive authentication attempts with two factor authentication methods in Checkmk 2.3 before 2.3.0p6 facilitates brute-forcing of second factor mechanisms.
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2024

CVE-2024-36971

Publication date:
10/06/2024
In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net: fix __dst_negative_advice() race<br /> <br /> __dst_negative_advice() does not enforce proper RCU rules when<br /> sk-&gt;dst_cache must be cleared, leading to possible UAF.<br /> <br /> RCU rules are that we must first clear sk-&gt;sk_dst_cache,<br /> then call dst_release(old_dst).<br /> <br /> Note that sk_dst_reset(sk) is implementing this protocol correctly,<br /> while __dst_negative_advice() uses the wrong order.<br /> <br /> Given that ip6_negative_advice() has special logic<br /> against RTF_CACHE, this means each of the three -&gt;negative_advice()<br /> existing methods must perform the sk_dst_reset() themselves.<br /> <br /> Note the check against NULL dst is centralized in<br /> __dst_negative_advice(), there is no need to duplicate<br /> it in various callbacks.<br /> <br /> Many thanks to Clement Lecigne for tracking this issue.<br /> <br /> This old bug became visible after the blamed commit, using UDP sockets.
Severity CVSS v4.0: Pending analysis
Last modification:
05/11/2025

CVE-2024-4745

Publication date:
10/06/2024
Missing Authorization vulnerability in RafflePress Giveaways and Contests by RafflePress.This issue affects Giveaways and Contests by RafflePress: from n/a through 1.12.4.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2024

CVE-2024-4746

Publication date:
10/06/2024
Missing Authorization vulnerability in netgsm Netgsm netgsm allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Netgsm: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2026

CVE-2024-35735

Publication date:
10/06/2024
Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.2.11.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2024

CVE-2024-35741

Publication date:
10/06/2024
Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2024

CVE-2024-35742

Publication date:
10/06/2024
Missing Authorization vulnerability in Code Parrots Easy Forms for Mailchimp.This issue affects Easy Forms for Mailchimp: from n/a through 6.9.0.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2024

CVE-2024-4328

Publication date:
10/06/2024
A Cross-Site Request Forgery (CSRF) vulnerability exists in the clear_personality_files_list function of the parisneo/lollms-webui v9.6. The vulnerability arises from the use of a GET request to clear personality files list, which lacks proper CSRF protection. This flaw allows attackers to trick users into performing actions without their consent, such as deleting important files on the system. The issue is present in the application&amp;#39;s handling of requests, making it susceptible to CSRF attacks that could lead to unauthorized actions being performed on behalf of the user.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2024

CVE-2024-4744

Publication date:
10/06/2024
Missing Authorization vulnerability in Avirtum iPages Flipbook.This issue affects iPages Flipbook: from n/a through 1.5.1.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2024

CVE-2024-35725

Publication date:
10/06/2024
Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.3.6.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2024

CVE-2024-35726

Publication date:
10/06/2024
Missing Authorization vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.19.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2024

CVE-2024-35727

Publication date:
10/06/2024
Missing Authorization vulnerability in actpro Extra Product Options for WooCommerce.This issue affects Extra Product Options for WooCommerce: from n/a through 3.0.6.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2024