Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-26982

Publication date:
29/03/2023
Trudesk v1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter under the Create Ticket function.
Severity CVSS v4.0: Pending analysis
Last modification:
18/02/2025

CVE-2023-1575

Publication date:
29/03/2023
The Mega Main Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2026

CVE-2023-1663

Publication date:
29/03/2023
Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthorized actors. The root cause of this vulnerability is an insecurely configured servlet mapping for the underlying Apache Tomcat server. As a result, the downloads directory and its contents are accessible. 5.9 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L/E:P/RL:O/RC:C)
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-28158

Publication date:
29/03/2023
Privilege escalation via stored XSS using the file upload service to upload malicious content.<br /> The issue can be exploited only by authenticated users which can create directory name to inject some XSS content and gain some privileges such admin user.
Severity CVSS v4.0: Pending analysis
Last modification:
13/02/2025

CVE-2023-23861

Publication date:
29/03/2023
Cross-Site Request Forgery (CSRF) vulnerability in German Mesky GMAce plugin
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2022-48432

Publication date:
29/03/2023
In JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn&amp;#39;t sandboxed.
Severity CVSS v4.0: Pending analysis
Last modification:
01/04/2023

CVE-2022-48433

Publication date:
29/03/2023
In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.
Severity CVSS v4.0: Pending analysis
Last modification:
01/04/2023

CVE-2022-38077

Publication date:
29/03/2023
Cross-Site Request Forgery (CSRF) vulnerability in WP OnlineSupport, Essential Plugin Popup Anything – A Marketing Popup and Lead Generation Conversions plugin
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2022-47438

Publication date:
29/03/2023
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2022-47444

Publication date:
29/03/2023
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress plugin
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2022-48431

Publication date:
29/03/2023
In JetBrains IntelliJ IDEA before 2023.1 in some cases, Gradle and Maven projects could be imported without the “Trust Project” confirmation.
Severity CVSS v4.0: Pending analysis
Last modification:
01/04/2023

CVE-2022-48430

Publication date:
29/03/2023
In JetBrains IntelliJ IDEA before 2023.1 file content could be disclosed via an external stylesheet path in Markdown preview.
Severity CVSS v4.0: Pending analysis
Last modification:
01/04/2023