Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-26922

Publication date:
08/03/2023
SQL injection vulnerability found in Varisicte matrix-gui v.2 allows a remote attacker to execute arbitrary code via the shell_exect parameter to the \www\pages\matrix-gui-2.0 endpoint.
Severity CVSS v4.0: Pending analysis
Last modification:
04/03/2025

CVE-2023-26261

Publication date:
08/03/2023
In UBIKA WAAP Gateway/Cloud through 6.10, a blind XPath injection leads to an authentication bypass by stealing the session of another connected user. The fixed versions are WAAP Gateway & Cloud 6.11.0 and 6.5.6-patch15.
Severity CVSS v4.0: Pending analysis
Last modification:
05/03/2025

CVE-2023-26952

Publication date:
08/03/2023
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Menu module.
Severity CVSS v4.0: Pending analysis
Last modification:
03/03/2025

CVE-2023-1270

Publication date:
08/03/2023
Cross-site Scripting in GitHub repository btcpayserver/btcpayserver prior to 1.8.3.
Severity CVSS v4.0: Pending analysis
Last modification:
01/02/2024

CVE-2023-25395

Publication date:
08/03/2023
TOTOlink A7100RU V7.4cu.2313_B20191024 router was discovered to contain a command injection vulnerability via the ou parameter at /setting/delStaticDhcpRules.
Severity CVSS v4.0: Pending analysis
Last modification:
08/03/2024

CVE-2023-26950

Publication date:
08/03/2023
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Title parameter under the Adding Categories module.
Severity CVSS v4.0: Pending analysis
Last modification:
05/03/2025

CVE-2023-1267

Publication date:
08/03/2023
Improper Neutralization of Special Elements used in an SQL Command (&amp;#39;SQL Injection&amp;#39;) vulnerability in Ulkem Company PtteM Kart.This issue affects PtteM Kart: before 2.1.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-23638

Publication date:
08/03/2023
A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. <br /> <br /> This issue affects Apache Dubbo 2.7.x version 2.7.21 and prior versions; Apache Dubbo 3.0.x version 3.0.13 and prior versions; Apache Dubbo 3.1.x version 3.1.5 and prior versions.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-1269

Publication date:
08/03/2023
Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
Severity CVSS v4.0: Pending analysis
Last modification:
14/03/2023

CVE-2023-24657

Publication date:
08/03/2023
phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php.
Severity CVSS v4.0: Pending analysis
Last modification:
05/03/2025

CVE-2023-0090

Publication date:
08/03/2023
The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through &amp;#39;eval injection&amp;#39;. Exploitation requires network access to the webservices API, but such access is a non-standard configuration. This affects all versions 8.20.0 and below.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2023

CVE-2023-0089

Publication date:
08/03/2023
<br /> The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to execute remote code through &amp;#39;eval injection&amp;#39;.<br /> <br /> This affects all versions 8.20.0 and below. <br /> <br /> <br /> <br /> <br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023