Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-41611

Publication date:
30/07/2024
In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.
Severity CVSS v4.0: Pending analysis
Last modification:
29/09/2025

CVE-2024-41945

Publication date:
30/07/2024
fuels-ts is a library for interacting with Fuel v2. The typescript SDK has no awareness of to-be-spent transactions causing some transactions to fail or silently get pruned as they are funded with already used UTXOs. The problem occurs, because the `fund` function in `fuels-ts/packages/account/src/account.ts` gets the needed ressources statelessly with the function `getResourcesToSpend` without taking into consideration already used UTXOs. This issue will lead to unexpected SDK behaviour, such as a transaction not getting included in the `txpool` / in a block or a previous transaction silently getting removed from the `txpool` and replaced with a new one.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2024

CVE-2023-33976

Publication date:
30/07/2024
TensorFlow is an end-to-end open source platform for machine learning. `array_ops.upper_bound` causes a segfault when not given a rank 2 tensor. The fix will be included in TensorFlow 2.13 and will also cherrypick this commit on TensorFlow 2.12.
Severity CVSS v4.0: Pending analysis
Last modification:
01/10/2024

CVE-2024-36572

Publication date:
30/07/2024
Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the functions setDefaults, mergeBranch, and Object.setObjectValue.
Severity CVSS v4.0: Pending analysis
Last modification:
08/08/2024

CVE-2024-38984

Publication date:
30/07/2024
Prototype Pollution in lukebond json-override 0.2.0 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via the __proto__ property.
Severity CVSS v4.0: Pending analysis
Last modification:
08/08/2024

CVE-2024-38986

Publication date:
30/07/2024
Prototype Pollution in 75lb deep-merge 1.1.1 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via merge methods of lodash to merge objects.
Severity CVSS v4.0: Pending analysis
Last modification:
08/08/2024

CVE-2024-41438

Publication date:
30/07/2024
A heap buffer overflow in the function cp_stored() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) via a crafted PNG file.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2025

CVE-2024-41439

Publication date:
30/07/2024
A heap buffer overflow in the function cp_block() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) via a crafted PNG file.
Severity CVSS v4.0: Pending analysis
Last modification:
22/10/2024

CVE-2024-41440

Publication date:
30/07/2024
A heap buffer overflow in the function png_quantize() of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) via a crafted PNG file.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2025

CVE-2024-41443

Publication date:
30/07/2024
A stack overflow in the function cp_dynamic() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) via a crafted PNG file.
Severity CVSS v4.0: Pending analysis
Last modification:
19/03/2025

CVE-2024-5249

Publication date:
30/07/2024
In versions of Akana API Platform prior to 2024.1.0, SAML tokens can be replayed.
Severity CVSS v4.0: Pending analysis
Last modification:
01/10/2024

CVE-2024-5250

Publication date:
30/07/2024
In versions of Akana API Platform prior to 2024.1.0 overly verbose errors can be found in SAML integrations
Severity CVSS v4.0: Pending analysis
Last modification:
01/10/2024