Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-23598

Publication date:
02/06/2023
Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website could arbitrarily read a file via a call to `DataTransfer.setData`. This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
18/12/2025

CVE-2023-23599

Publication date:
02/06/2023
When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
18/12/2025

CVE-2023-23600

Publication date:
02/06/2023
Per origin notification permissions were being stored in a way that didn&amp;#39;t take into account what browsing context the permission was granted in. This lead to the possibility of notifications to be displayed during different browsing sessions.<br /> *This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
18/12/2025

CVE-2023-23601

Publication date:
02/06/2023
Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
18/12/2025

CVE-2023-23602

Publication date:
02/06/2023
A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from inside WebWorkers. This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
18/12/2025

CVE-2023-23603

Publication date:
02/06/2023
Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` weren&amp;#39;t accounting for external URLs. Data could then be potentially exfiltrated from the browser. This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
18/12/2025

CVE-2023-23604

Publication date:
02/06/2023
A duplicate `SystemPrincipal` object could be created when parsing a non-system html document via `DOMParser::ParseFromSafeString`. This could have lead to bypassing web security checks. This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
18/12/2025

CVE-2023-23605

Publication date:
02/06/2023
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108 and Firefox ESR 102.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
18/12/2025

CVE-2023-23606

Publication date:
02/06/2023
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
18/12/2025

CVE-2023-3068

Publication date:
02/06/2023
A vulnerability classified as critical has been found in Campcodes Retro Cellphone Online Store 1.0. Affected is an unknown function of the file /admin/modal_add_product.php. The manipulation of the argument category leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230580.
Severity CVSS v4.0: Pending analysis
Last modification:
17/05/2024

CVE-2023-3067

Publication date:
02/06/2023
Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.59.4.
Severity CVSS v4.0: Pending analysis
Last modification:
09/06/2023

CVE-2023-2687

Publication date:
02/06/2023
Buffer overflow in Platform CLI component in Silicon Labs Gecko SDK v4.2.1 and earlier allows user to overwrite limited structures on the heap.
Severity CVSS v4.0: Pending analysis
Last modification:
25/09/2024