Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-4132

Publication date:
03/08/2023
A use-after-free vulnerability was found in the siano smsusb module in the Linux kernel. The bug occurs during device initialization when the siano device is plugged in. This flaw allows a local user to crash the system, causing a denial of service condition.
Severity CVSS v4.0: Pending analysis
Last modification:
13/09/2024

CVE-2023-3766

Publication date:
03/08/2023
A vulnerability was discovered in the odoh-rs rust crate that stems from faulty logic during the parsing of encrypted queries. This issue specifically occurs when processing encrypted query data received from remote clients and enables an attacker with knowledge of this vulnerability to craft and send specially designed encrypted queries to targeted ODOH servers running with odoh-rs. Upon successful exploitation, the server will crash abruptly, disrupting its normal operation and rendering the service temporarily unavailable.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2023

CVE-2023-3348

Publication date:
03/08/2023
The Wrangler command line tool  (
Severity CVSS v4.0: Pending analysis
Last modification:
29/08/2023

CVE-2023-3180

Publication date:
03/08/2023
A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption requests in virtio_crypto_handle_sym_req. There is no check for the value of `src_len` and `dst_len` in virtio_crypto_sym_op_helper, potentially leading to a heap buffer overflow when the two values differ.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-39097

Publication date:
03/08/2023
WebBoss.io CMS v3.7.0.1 contains a stored cross-site scripting (XSS) vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
07/08/2023

CVE-2023-39096

Publication date:
03/08/2023
WebBoss.io CMS v3.7.0.1 contains a stored Cross-Site Scripting (XSS) vulnerability due to lack of input validation and output encoding.
Severity CVSS v4.0: Pending analysis
Last modification:
07/08/2023

CVE-2023-38812

Publication date:
03/08/2023
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-36299

Publication date:
03/08/2023
A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and options-general parameters in index.php.
Severity CVSS v4.0: Pending analysis
Last modification:
07/08/2023

CVE-2023-36298

Publication date:
03/08/2023
DedeCMS v5.7.109 has a File Upload vulnerability, leading to remote code execution (RCE).
Severity CVSS v4.0: Pending analysis
Last modification:
07/08/2023

CVE-2023-2754

Publication date:
03/08/2023
The Cloudflare WARP client for Windows assigns loopback IPv4 addresses for the DNS Servers, since WARP acts as local DNS server that performs DNS queries in a secure manner, however, if a user is connected to WARP over an IPv6-capable network, te WARP client did not assign loopback IPv6 addresses but Unique Local Addresses, which under certain conditions could point towards unknown devices in the same local network which enables an Attacker to view DNS queries made by the device.<br /> <br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
09/08/2023

CVE-2023-28468

Publication date:
03/08/2023
An issue was discovered in FvbServicesRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The FvbServicesRuntimeDxe SMM module exposes an SMI handler that allows an attacker to interact with the SPI flash at run-time from the OS.
Severity CVSS v4.0: Pending analysis
Last modification:
09/08/2023

CVE-2023-25600

Publication date:
03/08/2023
An issue was discovered in InsydeH2O. A malicious operating system can tamper with a runtime-writable EFI variable, leading to out-of-bounds memory reads and a denial of service. This is fixed in version 01.01.04.0016.
Severity CVSS v4.0: Pending analysis
Last modification:
08/08/2023