Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-0750

Publication date:
06/04/2023
Yellobrik PEC-1864 implements authentication checks via javascript in the frontend interface.  When the device can be accessed over the network an attacker could bypass authentication.<br /> <br /> <br /> <br /> <br /> This would allow an attacker to : <br /> - Change the password, resulting in a DOS of the users<br /> <br /> - Change the streaming source, compromising the integrity of the stream<br /> <br /> - Change the streaming destination, compromising the confidentiality of the stream<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> This issue affects Yellowbrik: PEC 1864. No patch has been issued by the manufacturer as this model was discontinued.<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-1908

Publication date:
06/04/2023
A vulnerability was found in SourceCodester Simple Mobile Comparison Website 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/categories/view_category.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-225150 is the identifier assigned to this vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
17/05/2024

CVE-2022-46793

Publication date:
06/04/2023
Cross-Site Request Forgery (CSRF) vulnerability in AdTribes.Io Product Feed PRO for WooCommerce plugin
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-23801

Publication date:
06/04/2023
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Really Simple Google Tag Manager plugin
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-24411

Publication date:
06/04/2023
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Kerry Kline BNE Testimonials plugin
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-24403

Publication date:
06/04/2023
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP For The Win bbPress Voting plugin
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-24387

Publication date:
06/04/2023
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPdevart Organization chart plugin
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-24383

Publication date:
06/04/2023
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Namaste! LMS plugin
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-23898

Publication date:
06/04/2023
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeThemes Blocksy Companion plugin
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-0652

Publication date:
06/04/2023
Due to a hardlink created in the ProgramData folder during the repair process of the software, the installer (MSI) of WARP Client for Windows (
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-24002

Publication date:
06/04/2023
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPdevart YouTube Embed, Playlist and Popup by WpDevArt plugin
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-24003

Publication date:
06/04/2023
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Timersys WP Popups – WordPress Popup plugin
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023