Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-37303

Publication date:
03/12/2024
Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote participants to trigger a download and caching of remote media from a remote homeserver to the local media repository. Such content then also becomes available for download from the local homeserver in an unauthenticated way. The implication is that unauthenticated remote adversaries can use this functionality to plant problematic content into the media repository. Synapse 1.106 introduces a partial mitigation in the form of new endpoints which require authentication for media downloads. The unauthenticated endpoints will be frozen in a future release, closing the attack vector.
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2025

CVE-2024-25019

Publication date:
03/12/2024
IBM Cognos Controller 11.0.0 and 11.0.1 <br /> <br /> could be vulnerable to malicious file upload by not validating the type of file uploaded to Journal entry attachments. Attackers can make use of this weakness and upload malicious executable files into the system that can be sent to victims for performing further attacks.
Severity CVSS v4.0: Pending analysis
Last modification:
11/12/2024

CVE-2024-25035

Publication date:
03/12/2024
IBM Cognos Controller 11.0.0 and 11.0.1 <br /> <br /> <br /> <br /> exposes server details that could allow an attacker to obtain information of the application environment to conduct further attacks.
Severity CVSS v4.0: Pending analysis
Last modification:
11/12/2024

CVE-2024-25036

Publication date:
03/12/2024
IBM Cognos Controller 11.0.0 and 11.0.1 <br /> <br /> <br /> <br /> <br /> <br /> could allow an authenticated user with local access to bypass security allowing users to circumvent restrictions imposed on input fields.
Severity CVSS v4.0: Pending analysis
Last modification:
11/12/2024

CVE-2021-29892

Publication date:
03/12/2024
IBM Cognos Controller 11.0.0 and 11.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Severity CVSS v4.0: Pending analysis
Last modification:
11/12/2024

CVE-2024-53999

Publication date:
03/12/2024
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The application allows users to upload files with scripts in the filename parameter. As a result, a malicious user can upload a script file to the system. When users in the application use the "Diff or Compare" functionality, they are affected by a Stored Cross-Site Scripting vulnerability. This vulnerability is fixed in 4.2.9.
Severity CVSS v4.0: Pending analysis
Last modification:
27/06/2025

CVE-2024-54000

Publication date:
03/12/2024
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In versions prior to 3.9.7, the requests.get() request in the _check_url method is specified as allow_redirects=True, which allows a server-side request forgery when a request to .well-known/assetlinks.json" returns a 302 redirect. This is a bypass of the fix for CVE-2024-29190 and is fixed in 3.9.7.
Severity CVSS v4.0: Pending analysis
Last modification:
27/06/2025

CVE-2024-53257

Publication date:
03/12/2024
Vitess is a database clustering system for horizontal scaling of MySQL. The /debug/querylogz and /debug/env pages for vtgate and vttablet do not properly escape user input. The result is that queries executed by Vitess can write HTML into the monitoring page at will. These pages are rendered using text/template instead of rendering with a proper HTML templating engine. This vulnerability is fixed in 21.0.1, 20.0.4, and 19.0.8.
Severity CVSS v4.0: Pending analysis
Last modification:
03/12/2024

CVE-2024-12101

Publication date:
03/12/2024
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.
Severity CVSS v4.0: Pending analysis
Last modification:
03/12/2024

CVE-2024-11391

Publication date:
03/12/2024
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the &amp;#39;class_fma_connector.php&amp;#39; file in all versions up to, and including, 5.2.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload arbitrary files on the affected site&amp;#39;s server which may make remote code execution possible.
Severity CVSS v4.0: Pending analysis
Last modification:
05/06/2025

CVE-2024-11200

Publication date:
03/12/2024
The Goodlayers Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘font-family’ parameter in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Severity CVSS v4.0: Pending analysis
Last modification:
03/12/2024

CVE-2024-9978

Publication date:
03/12/2024
in OpenHarmony v4.1.1 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
Severity CVSS v4.0: Pending analysis
Last modification:
11/12/2024