Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-25608

Publication date:
20/02/2024
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions can be circumvented by using the 'REPLACEMENT CHARACTER' (U+FFFD), which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` parameter (2) `FORWARD_URL` parameter, (3) `noSuchEntryRedirect` parameter, and (4) others parameters that rely on HtmlUtil.escapeRedirect.
Severity CVSS v4.0: Pending analysis
Last modification:
11/12/2024

CVE-2024-25609

Publication date:
20/02/2024
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 service pack 3, 7.2 fix pack 15 through 18, and older unsupported versions can be circumvented by using two forward slashes, which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` parameter (2) `FORWARD_URL` parameter, and (3) others parameters that rely on HtmlUtil.escapeRedirect. This vulnerability is the result of an incomplete fix in CVE-2022-28977.
Severity CVSS v4.0: Pending analysis
Last modification:
11/12/2024

CVE-2023-49250

Publication date:
20/02/2024
Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server.<br /> <br /> This issue affects Apache DolphinScheduler: before 3.2.0.<br /> <br /> Users are recommended to upgrade to version 3.2.1, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
18/03/2025

CVE-2023-50270

Publication date:
20/02/2024
Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change.<br /> <br /> Users are recommended to upgrade to version 3.2.1, which fixes this issue.
Severity CVSS v4.0: Pending analysis
Last modification:
18/03/2025

CVE-2023-51770

Publication date:
20/02/2024
Arbitrary File Read Vulnerability in Apache Dolphinscheduler.<br /> <br /> This issue affects Apache DolphinScheduler: before 3.2.1. <br /> <br /> We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
27/03/2025

CVE-2023-49109

Publication date:
20/02/2024
Exposure of Remote Code Execution in Apache Dolphinscheduler.<br /> <br /> This issue affects Apache DolphinScheduler: before 3.2.1. <br /> <br /> We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
18/03/2025

CVE-2024-25604

Publication date:
20/02/2024
Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions does not properly check user permissions, which allows remote authenticated users with the VIEW user permission to edit their own permission via the User and Organizations section of the Control Panel.
Severity CVSS v4.0: Pending analysis
Last modification:
10/12/2024

CVE-2024-25605

Publication date:
20/02/2024
The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions grants guest users view permission to web content templates by default, which allows remote attackers to view any template via the UI or API.
Severity CVSS v4.0: Pending analysis
Last modification:
10/12/2024

CVE-2024-25606

Publication date:
20/02/2024
XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.3 before update 12, 7.2 before fix pack 20, and older unsupported versions allows attackers with permission to deploy widgets/portlets/extensions to obtain sensitive information or consume system resources via the Java2WsddTask._format method.
Severity CVSS v4.0: Pending analysis
Last modification:
11/12/2024

CVE-2024-1608

Publication date:
20/02/2024
In OPPO Usercenter Credit SDK, there&amp;#39;s a possible escalation of privilege due to loose permission check, This could lead to application internal information leak w/o user interaction.
Severity CVSS v4.0: Pending analysis
Last modification:
02/04/2025

CVE-2024-25150

Publication date:
20/02/2024
Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions allows remote authenticated users to obtain a user&amp;#39;s full name from the page&amp;#39;s title by enumerating user screen names.
Severity CVSS v4.0: Pending analysis
Last modification:
10/12/2024

CVE-2024-25973

Publication date:
20/02/2024
The Frentix GmbH OpenOlat LMS is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities. An attacker with rights to create or edit groups can create a course with a name that contains an XSS payload. Furthermore, attackers with the permissions to create or rename a catalog (sub-category) can enter unfiltered input in the name field. In addition, attackers who are allowed to create curriculums can also enter unfiltered input in the name field. This allows an attacker to execute stored JavaScript code with the permissions of the victim in the context of the user&amp;#39;s browser.
Severity CVSS v4.0: Pending analysis
Last modification:
14/03/2025