Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-45132

Publication date:
18/11/2022
In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validating device configuration files in lava-server loads input as a Jinja2 template in a way that can be used to trigger remote code execution in the LAVA server.
Severity CVSS v4.0: Pending analysis
Last modification:
30/04/2025

CVE-2022-44740

Publication date:
18/11/2022
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Creative Mail plugin
Severity CVSS v4.0: Pending analysis
Last modification:
23/11/2022

CVE-2022-45073

Publication date:
18/11/2022
Cross-Site Request Forgery (CSRF) vulnerability in REST API Authentication plugin
Severity CVSS v4.0: Pending analysis
Last modification:
22/11/2022

CVE-2022-45163

Publication date:
18/11/2022
An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i.MX RT 1015, i.MX RT 1020, i.MX RT 1050, i.MX RT 1060, i.MX 6 Family, i.MX 7Dual/Solo, i.MX 7ULP, i.MX 8M Quad, i.MX 8M Mini, and Vybrid. In a device security-enabled configuration, memory contents could potentially leak to physically proximate attackers via the respective SDP port in cold and warm boot attacks. (The recommended mitigation is to completely disable the SDP mode by programming a one-time programmable eFUSE. Customers can contact NXP for additional information.)
Severity CVSS v4.0: Pending analysis
Last modification:
30/04/2025

CVE-2022-42698

Publication date:
18/11/2022
Unauth. Arbitrary File Upload vulnerability in WordPress Api2Cart Bridge Connector plugin
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2022

CVE-2022-44583

Publication date:
18/11/2022
Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin
Severity CVSS v4.0: Pending analysis
Last modification:
20/02/2025

CVE-2022-42883

Publication date:
18/11/2022
Sensitive Information Disclosure vulnerability discovered by Quiz And Survey Master plugin
Severity CVSS v4.0: Pending analysis
Last modification:
22/11/2022

CVE-2022-43492

Publication date:
18/11/2022
Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress.
Severity CVSS v4.0: Pending analysis
Last modification:
20/02/2025

CVE-2022-44634

Publication date:
18/11/2022
Auth. (admin+) Arbitrary File Read vulnerability in S2W – Import Shopify to WooCommerce plugin
Severity CVSS v4.0: Pending analysis
Last modification:
20/02/2025

CVE-2022-44584

Publication date:
18/11/2022
Unauth. Arbitrary File Deletion vulnerability in WatchTowerHQ plugin
Severity CVSS v4.0: Pending analysis
Last modification:
08/08/2023

CVE-2022-42497

Publication date:
18/11/2022
Arbitrary Code Execution vulnerability in Api2Cart Bridge Connector plugin
Severity CVSS v4.0: Pending analysis
Last modification:
20/02/2025

CVE-2022-42459

Publication date:
18/11/2022
Auth. WordPress Options Change vulnerability in Image Hover Effects Ultimate plugin
Severity CVSS v4.0: Pending analysis
Last modification:
22/11/2022