Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-7421

Publication date:
25/09/2024
An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions
Severity CVSS v4.0: Pending analysis
Last modification:
17/03/2025

CVE-2024-46485

Publication date:
25/09/2024
dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2025

CVE-2024-46600

Publication date:
25/09/2024
dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.php?act=delCate&id=31
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2025

CVE-2024-47078

Publication date:
25/09/2024
Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or private MQTT Server. Nodes can communicate directly via an internet connection or proxied through a connected phone (i.e., via bluetooth). Prior to version 2.5.1, multiple weaknesses in the MQTT implementation allow for authentication and authorization bypasses resulting in unauthorized control of MQTT-connected nodes. Version 2.5.1 contains a patch.
Severity CVSS v4.0: Pending analysis
Last modification:
02/12/2024

CVE-2024-44825

Publication date:
25/09/2024
Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrary files unto the system via a crafted .inv3 file.
Severity CVSS v4.0: Pending analysis
Last modification:
13/02/2026

CVE-2023-25189

Publication date:
25/09/2024
BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web Element Manager, regardless of the access privileges, having a possibility to read BTS service operation details performed by Nokia Care service personnel via SSH.
Severity CVSS v4.0: Pending analysis
Last modification:
29/10/2024

CVE-2024-46461

Publication date:
25/09/2024
VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
26/09/2024

CVE-2024-43237

Publication date:
25/09/2024
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in TaxoPress WordPress Tag Cloud Plugin – Tag Groups.This issue affects WordPress Tag Cloud Plugin – Tag Groups: from n/a through 2.0.3.
Severity CVSS v4.0: Pending analysis
Last modification:
26/09/2024

CVE-2024-43959

Publication date:
25/09/2024
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themepoints Testimonials allows Reflected XSS.This issue affects Testimonials: from n/a through 3.0.8.
Severity CVSS v4.0: Pending analysis
Last modification:
26/09/2024

CVE-2024-43990

Publication date:
25/09/2024
Insertion of Sensitive Information into Log File vulnerability in StylemixThemes Masterstudy LMS Starter.This issue affects Masterstudy LMS Starter: from n/a through 1.1.8.
Severity CVSS v4.0: Pending analysis
Last modification:
26/09/2024

CVE-2024-30128

Publication date:
25/09/2024
HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask their original source IP address. This may enable an attacker to trick the user into exposing sensitive information.
Severity CVSS v4.0: Pending analysis
Last modification:
30/10/2025

CVE-2024-22892

Publication date:
25/09/2024
OpenSlides 4.0.15 was discovered to be using a weak hashing algorithm to store passwords.
Severity CVSS v4.0: Pending analysis
Last modification:
14/03/2025