Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-51775

Publication date:
29/02/2024
The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2025

CVE-2023-51779

Publication date:
29/02/2024
bt_sock_recvmsg in net/bluetooth/af_bluetooth.c in the Linux kernel through 6.6.8 has a use-after-free because of a bt_sock_ioctl race condition.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2023-50658

Publication date:
29/02/2024
The jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
Severity CVSS v4.0: Pending analysis
Last modification:
14/02/2025

CVE-2023-50436

Publication date:
29/02/2024
An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The earliest affected version is 7.1.5.
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2025

CVE-2023-50437

Publication date:
29/02/2024
An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverGroups and engageCluster2.
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2025

CVE-2023-49930

Publication date:
29/02/2024
An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.
Severity CVSS v4.0: Pending analysis
Last modification:
28/03/2025

CVE-2023-49931

Publication date:
29/02/2024
An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2025

CVE-2023-49932

Publication date:
29/02/2024
An issue was discovered in Couchbase Server before 7.2.4. An attacker can bypass SQL++ N1QL cURL host restrictions.
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2025

CVE-2023-49337

Publication date:
29/02/2024
Concrete CMS before 9.2.3 allows Stored XSS on the Admin Dashboard via /dashboard/system/basics/name. (8.5 and earlier are unaffected.)
Severity CVSS v4.0: Pending analysis
Last modification:
16/12/2024

CVE-2023-48650

Publication date:
29/02/2024
Concrete CMS before 8.5.14 and 9 before 9.2.3 is vulnerable to an admin adding a stored XSS payload via the Layout Preset name.
Severity CVSS v4.0: Pending analysis
Last modification:
16/12/2024

CVE-2023-48651

Publication date:
29/02/2024
Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) at /ccm/system/dialogs/file/delete/1/submit.
Severity CVSS v4.0: Pending analysis
Last modification:
16/12/2024

CVE-2023-48653

Publication date:
29/02/2024
Concrete CMS before 8.5.14 and 9 before 9.2.3 allows Cross Site Request Forgery (CSRF) via ccm/calendar/dialogs/event/delete/submit. An attacker can force an admin to delete events on the site because the event ID is numeric and sequential.
Severity CVSS v4.0: Pending analysis
Last modification:
16/12/2024