Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-2345

Publication date:
27/04/2023
A vulnerability was found in SourceCodester Service Provider Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=delete_inquiry. The manipulation leads to improper authorization. The attack may be launched remotely. The identifier of this vulnerability is VDB-227588.
Severity CVSS v4.0: Pending analysis
Last modification:
17/05/2024

CVE-2023-30847

Publication date:
27/04/2023
H2O is an HTTP server. In versions 2.3.0-beta2 and prior, when the reverse proxy handler tries to processes a certain type of invalid HTTP request, it tries to build an upstream URL by reading from uninitialized pointer. This behavior can lead to crashes or leak of information to back end HTTP servers. Pull request number 3229 fixes the issue. The pull request has been merged to the `master` branch in commit f010336. Users should upgrade to commit f010336 or later.
Severity CVSS v4.0: Pending analysis
Last modification:
09/05/2023

CVE-2023-30349

Publication date:
27/04/2023
JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function.
Severity CVSS v4.0: Pending analysis
Last modification:
31/01/2025

CVE-2023-2341

Publication date:
27/04/2023
Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.
Severity CVSS v4.0: Pending analysis
Last modification:
04/05/2023

CVE-2023-2343

Publication date:
27/04/2023
Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21.
Severity CVSS v4.0: Pending analysis
Last modification:
04/05/2023

CVE-2023-2344

Publication date:
27/04/2023
A vulnerability has been found in SourceCodester Service Provider Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=save_service of the component HTTP POST Request Handler. The manipulation of the argument name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227587.
Severity CVSS v4.0: Pending analysis
Last modification:
17/05/2024

CVE-2023-24966

Publication date:
27/04/2023
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 246904.
Severity CVSS v4.0: Pending analysis
Last modification:
04/05/2023

CVE-2023-2342

Publication date:
27/04/2023
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.
Severity CVSS v4.0: Pending analysis
Last modification:
04/05/2023

CVE-2023-30444

Publication date:
27/04/2023
IBM Watson Machine Learning on Cloud Pak for Data 4.0 and 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 253350.
Severity CVSS v4.0: Pending analysis
Last modification:
04/05/2023

CVE-2023-2340

Publication date:
27/04/2023
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.
Severity CVSS v4.0: Pending analysis
Last modification:
04/05/2023

CVE-2023-29255

Publication date:
27/04/2023
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as it may trap when compiling a variation of an anonymous block. IBM X-Force ID: 251991.
Severity CVSS v4.0: Pending analysis
Last modification:
11/05/2023

CVE-2023-2331

Publication date:
27/04/2023
Unquoted service Path or Element vulnerability in 42Gears Surelock Windows SureLock Service (NixService.Exe) on Windows application will allows to insert arbitrary code into the service.<br /> This issue affects Surelock Windows : from 2.3.12 through 2.40.0.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
08/05/2023