Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-2636

Publication date:
19/03/2024
An Unrestricted Upload of File vulnerability has been found on Cegid Meta4 HR, that allows an attacker to upload malicios files to the server via '/config/espanol/update_password.jsp' file. Modifying the 'M4_NEW_PASSWORD' parameter, an attacker could store a malicious JSP file inside the file directory, to be executed the the file is loaded in the application.
Severity CVSS v4.0: Pending analysis
Last modification:
19/03/2024

CVE-2023-40279

Publication date:
19/03/2024
An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to main.do.
Severity CVSS v4.0: Pending analysis
Last modification:
01/08/2024

CVE-2024-29143

Publication date:
19/03/2024
Improper Neutralization of Input During Web Page Generation (&amp;#39;Cross-site Scripting&amp;#39;) vulnerability in Cozmoslabs, sareiodata Passwordless Login passwordless-login allows Stored XSS.This issue affects Passwordless Login: from n/a through 1.1.2.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
19/03/2024

CVE-2024-2611

Publication date:
19/03/2024
A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
01/04/2025

CVE-2024-2612

Publication date:
19/03/2024
If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2025

CVE-2024-2613

Publication date:
19/03/2024
Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash. This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
25/02/2025

CVE-2024-2614

Publication date:
19/03/2024
Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
25/02/2025

CVE-2024-2615

Publication date:
19/03/2024
Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
14/03/2025

CVE-2024-2616

Publication date:
19/03/2024
To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue. This vulnerability affects Firefox ESR
Severity CVSS v4.0: Pending analysis
Last modification:
25/02/2025

CVE-2024-2632

Publication date:
19/03/2024
A Information Exposure Vulnerability has been found on Meta4 HR. This vulnerability allows an attacker to obtain a lot of information about the application such as the variables set in the process, the Tomcat versions, library versions and underlying operation system via HTTP GET &amp;#39;/sitetest/english/dumpenv.jsp&amp;#39;.
Severity CVSS v4.0: Pending analysis
Last modification:
19/03/2024

CVE-2024-2633

Publication date:
19/03/2024
A Cross-Site Scripting Vulnerability has been found on Meta4 HR affecting version 819.001.022 and earlier. The endpoint &amp;#39;/sitetest/english/dumpenv.jsp&amp;#39; is vulnerable to XSS attack by &amp;#39;lang&amp;#39; query, i.e. &amp;#39;/sitetest/english/dumpenv.jsp?snoop=yes&amp;lang=%27%3Cimg%20src/onerror=alert(1)%3E&amp;params&amp;#39;.
Severity CVSS v4.0: Pending analysis
Last modification:
19/03/2024

CVE-2024-2634

Publication date:
19/03/2024
A Cross-Site Scripting Vulnerability has been found on Meta4 HR affecting version 819.001.022 and earlier. The endpoint &amp;#39;/sse_generico/generico_login.jsp&amp;#39; is vulnerable to XSS attack via &amp;#39;lang&amp;#39; query, i.e. &amp;#39;/sse_generico/generico_login.jsp?lang=%27%3balert(%27BLEUSS%27)%2f%2f&amp;params=&amp;#39;.
Severity CVSS v4.0: Pending analysis
Last modification:
19/03/2024