Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-21326

Publication date:
26/01/2024
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
11/06/2024

CVE-2024-21382

Publication date:
26/01/2024
Microsoft Edge for Android Information Disclosure Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
11/06/2024

CVE-2024-21383

Publication date:
26/01/2024
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
11/06/2024

CVE-2024-21385

Publication date:
26/01/2024
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
11/06/2024

CVE-2024-21387

Publication date:
26/01/2024
Microsoft Edge for Android Spoofing Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
11/06/2024

CVE-2024-0456

Publication date:
26/01/2024
An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able to assign arbitrary users to MRs that they created within the project
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2024

CVE-2023-5933

Publication date:
26/01/2024
An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.
Severity CVSS v4.0: Pending analysis
Last modification:
31/01/2024

CVE-2024-0402

Publication date:
26/01/2024
An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.
Severity CVSS v4.0: Pending analysis
Last modification:
31/01/2024

CVE-2024-23630

Publication date:
26/01/2024
An arbitrary firmware upload vulnerability exists in the Motorola <br /> MR2600. An attacker can exploit this vulnerability to achieve code <br /> execution on the device. Authentication is required, however can be <br /> bypassed.
Severity CVSS v4.0: Pending analysis
Last modification:
01/02/2024

CVE-2024-23627

Publication date:
26/01/2024
A command injection vulnerability exists in the &amp;#39;SaveStaticRouteIPv4Params&amp;#39; parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.
Severity CVSS v4.0: Pending analysis
Last modification:
01/02/2024

CVE-2024-23628

Publication date:
26/01/2024
A command injection vulnerability exists in the <br /> &amp;#39;SaveStaticRouteIPv6Params&amp;#39; parameter of the Motorola MR2600. A remote <br /> attacker can exploit this vulnerability to achieve command execution. <br /> Authentication is required, however can be bypassed.
Severity CVSS v4.0: Pending analysis
Last modification:
01/02/2024

CVE-2024-23629

Publication date:
26/01/2024
An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access protected URLs and retrieve sensitive information.<br />
Severity CVSS v4.0: Pending analysis
Last modification:
18/10/2024