Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-24260

Publication date:
05/02/2024
media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_subscribe_remove function at /uac/sip-uac-subscribe.c.
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2024

CVE-2024-24262

Publication date:
05/02/2024
media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_uac_stop_timer function at /uac/sip-uac-transaction.c.
Severity CVSS v4.0: Pending analysis
Last modification:
06/06/2025

CVE-2024-24263

Publication date:
05/02/2024
Lotos WebServer v0.1.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the response_append_status_line function at /lotos/src/response.c.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2025

CVE-2024-24265

Publication date:
05/02/2024
gpac v2.2.1 was discovered to contain a memory leak via the dst_props variable in the gf_filter_pid_merge_properties_internal function.
Severity CVSS v4.0: Pending analysis
Last modification:
09/05/2025

CVE-2024-24266

Publication date:
05/02/2024
gpac v2.2.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the dasher_configure_pid function at /src/filters/dasher.c.
Severity CVSS v4.0: Pending analysis
Last modification:
05/06/2025

CVE-2024-24267

Publication date:
05/02/2024
gpac v2.2.1 (fixed in v2.4.0) was discovered to contain a memory leak via the gfio_blob variable in the gf_fileio_from_blob function.
Severity CVSS v4.0: Pending analysis
Last modification:
26/09/2025

CVE-2024-24258

Publication date:
05/02/2024
freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function.
Severity CVSS v4.0: Pending analysis
Last modification:
04/11/2025

CVE-2024-24259

Publication date:
05/02/2024
freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function.
Severity CVSS v4.0: Pending analysis
Last modification:
04/11/2025

CVE-2023-6028

Publication date:
05/02/2024
A reflected<br /> cross-site scripting (XSS) vulnerability exists in the SVG version of System<br /> Diagnostics Manager of B&amp;R Automation Runtime versions
Severity CVSS v4.0: Pending analysis
Last modification:
09/02/2024

CVE-2023-6874

Publication date:
05/02/2024
Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number
Severity CVSS v4.0: Pending analysis
Last modification:
25/09/2024

CVE-2024-0953

Publication date:
05/02/2024
When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surprise the user and potentially direct them to unwanted content. This vulnerability affects Firefox for iOS
Severity CVSS v4.0: Pending analysis
Last modification:
27/10/2024

CVE-2024-23054

Publication date:
05/02/2024
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm).
Severity CVSS v4.0: Pending analysis
Last modification:
03/07/2024