Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-46523

Publication date:
25/10/2023
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function upgradeInfoRegister.
Severity CVSS v4.0: Pending analysis
Last modification:
11/09/2024

CVE-2023-46525

Publication date:
25/10/2023
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function loginRegister.
Severity CVSS v4.0: Pending analysis
Last modification:
11/09/2024

CVE-2023-46158

Publication date:
25/10/2023
IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to improper resource expiration handling. IBM X-Force ID: 268775.
Severity CVSS v4.0: Pending analysis
Last modification:
01/11/2023

CVE-2023-46189

Publication date:
25/10/2023
Cross-Site Request Forgery (CSRF) vulnerability in Simple Calendar – Google Calendar Plugin
Severity CVSS v4.0: Pending analysis
Last modification:
01/11/2023

CVE-2023-46190

Publication date:
25/10/2023
Cross-Site Request Forgery (CSRF) vulnerability in Novo-media Novo-Map : your WP posts on custom google maps plugin
Severity CVSS v4.0: Pending analysis
Last modification:
01/11/2023

CVE-2023-46191

Publication date:
25/10/2023
Cross-Site Request Forgery (CSRF) vulnerability in Niels van Renselaar Open Graph Metabox plugin
Severity CVSS v4.0: Pending analysis
Last modification:
01/11/2023

CVE-2023-46193

Publication date:
25/10/2023
Cross-Site Request Forgery (CSRF) vulnerability in Internet Marketing Ninjas Internal Link Building plugin
Severity CVSS v4.0: Pending analysis
Last modification:
01/11/2023

CVE-2023-46198

Publication date:
25/10/2023
Cross-Site Request Forgery (CSRF) vulnerability in Scientech It Solution Appointment Calendar plugin
Severity CVSS v4.0: Pending analysis
Last modification:
01/11/2023

CVE-2023-46202

Publication date:
25/10/2023
Cross-Site Request Forgery (CSRF) vulnerability in Jeff Sherk Auto Login New User After Registration plugin
Severity CVSS v4.0: Pending analysis
Last modification:
01/11/2023

CVE-2023-46204

Publication date:
25/10/2023
Cross-Site Request Forgery (CSRF) vulnerability in Muller Digital Inc. Duplicate Theme plugin
Severity CVSS v4.0: Pending analysis
Last modification:
01/11/2023

CVE-2023-46316

Publication date:
25/10/2023
In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3, the wrapper scripts do not properly parse command lines.
Severity CVSS v4.0: Pending analysis
Last modification:
03/07/2024

CVE-2023-46346

Publication date:
25/10/2023
In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 4.1.1 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a path traversal to view all files on the information system.
Severity CVSS v4.0: Pending analysis
Last modification:
11/09/2024