Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-33667

Publication date:
26/04/2024
An issue was discovered in Zammad before 6.3.0. An authenticated agent could perform a remote Denial of Service attack by calling an endpoint that accepts a generic method name, which was not properly sanitized against an allowlist.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2025

CVE-2024-33668

Publication date:
26/04/2024
An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no access to.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2025

CVE-2024-33669

Publication date:
26/04/2024
An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password API to more easily brute force passwords that are manually typed by the user.
Severity CVSS v4.0: Pending analysis
Last modification:
18/06/2025

CVE-2024-33670

Publication date:
26/04/2024
Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact the appearance and user interaction of the page.
Severity CVSS v4.0: Pending analysis
Last modification:
18/06/2025

CVE-2022-48682

Publication date:
26/04/2024
In deletefiles in FDUPES before 2.2.0, a TOCTOU race condition allows arbitrary file deletion via a symlink.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2024-33663

Publication date:
26/04/2024
python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.
Severity CVSS v4.0: Pending analysis
Last modification:
02/09/2025

CVE-2024-33664

Publication date:
26/04/2024
python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.
Severity CVSS v4.0: Pending analysis
Last modification:
02/09/2025

CVE-2024-32651

Publication date:
26/04/2024
changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host. Attackers can run any system command without any restriction and they could use a reverse shell. The impact is critical as the attacker can completely takeover the server machine. This can be reduced if changedetection is behind a login page, but this isn't required by the application (not by default and not enforced).
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2024-32868

Publication date:
26/04/2024
ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email. While ZITADEL already gives administrators the option to define a `Lockout Policy` with a maximum amount of failed password check attempts, there was no such mechanism for (T)OTP checks. This issue has been patched in version 2.50.0.<br />
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2025

CVE-2024-33661

Publication date:
26/04/2024
Portainer before 2.20.0 allows redirects when the target is not index.yaml.
Severity CVSS v4.0: Pending analysis
Last modification:
21/05/2025

CVE-2024-0916

Publication date:
25/04/2024
Unauthenticated file upload allows remote code execution.<br /> This issue affects UvDesk Community: from 1.0.0 through 1.1.3.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2024-3265

Publication date:
25/04/2024
The Advanced Search WordPress plugin through 1.1.6 does not properly escape parameters appended to an SQL query, making it possible for users with the administrator role to conduct SQL Injection attacks in the context of a multisite WordPress configurations.
Severity CVSS v4.0: Pending analysis
Last modification:
08/05/2025