Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-7521

Publication date:
06/08/2024
Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2024

CVE-2024-7529

Publication date:
06/08/2024
The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2024

CVE-2024-43114

Publication date:
06/08/2024
In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions
Severity CVSS v4.0: Pending analysis
Last modification:
11/09/2024

CVE-2024-6357

Publication date:
06/08/2024
Insecure Direct Object Reference vulnerability identified in OpenText ArcSight Intelligence.
Severity CVSS v4.0: Pending analysis
Last modification:
19/08/2024

CVE-2024-6358

Publication date:
06/08/2024
Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence.
Severity CVSS v4.0: Pending analysis
Last modification:
19/08/2024

CVE-2024-6359

Publication date:
06/08/2024
Privilege escalation vulnerability identified in OpenText ArcSight Intelligence.
Severity CVSS v4.0: Pending analysis
Last modification:
19/08/2024

CVE-2024-7518

Publication date:
06/08/2024
Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
29/10/2024

CVE-2024-33991

Publication date:
06/08/2024
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/eventwinner/index.php'.
Severity CVSS v4.0: Pending analysis
Last modification:
15/08/2024

CVE-2024-33992

Publication date:
06/08/2024
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/student/index.php'.
Severity CVSS v4.0: Pending analysis
Last modification:
15/08/2024

CVE-2024-33993

Publication date:
06/08/2024
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in /candidate/index.php'.
Severity CVSS v4.0: Pending analysis
Last modification:
15/08/2024

CVE-2024-33994

Publication date:
06/08/2024
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in '/event/index.php'.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2024

CVE-2024-33986

Publication date:
06/08/2024
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter in '/department/index.php'.
Severity CVSS v4.0: Pending analysis
Last modification:
15/08/2024