Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-40367

Publication date:
04/01/2024
A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied data when parsing DICOM files. This could result in an out-of-bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-15097)
Severity CVSS v4.0: Pending analysis
Last modification:
10/01/2024

CVE-2022-3864

Publication date:
04/01/2024
<br /> A vulnerability exists in the Relion update package signature validation. A tampered update package could cause the IED to restart. After restart the device is back to normal operation.<br /> An attacker could exploit the vulnerability by first gaining access to<br /> the system with security privileges and attempt to update the IED<br /> with a malicious update package. Successful exploitation of this<br /> vulnerability will cause the IED to restart, causing a temporary Denial of Service.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
10/01/2024

CVE-2023-6944

Publication date:
04/01/2024
A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded GitLab token includes a newline at the end of the string. The sanitized error can display on the frontend, including the raw access token. Upon gaining access to this token and depending on permissions, an attacker could push malicious code to repositories, delete resources in Git, revoke or generate new keys, and sign code illegitimately.
Severity CVSS v4.0: Pending analysis
Last modification:
05/09/2025

CVE-2023-7044

Publication date:
04/01/2024
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom ID in all versions up to, and including, 5.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access and higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2026

CVE-2022-2081

Publication date:
04/01/2024
A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is enabled and configured, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500 in a high rate, causing the targeted RTU500 CMU to reboot. The vulnerability is caused by a lack of flood control which eventually if exploited causes an internal stack overflow in the HCI Modbus TCP function.
Severity CVSS v4.0: Pending analysis
Last modification:
25/09/2024

CVE-2023-50630

Publication date:
04/01/2024
Cross Site Scripting (XSS) vulnerability in xiweicheng TMS v.2.28.0 allows a remote attacker to execute arbitrary code via a crafted script to the click here function.
Severity CVSS v4.0: Pending analysis
Last modification:
17/04/2025

CVE-2023-41784

Publication date:
04/01/2024
<br /> Permissions and Access Control Vulnerability in ZTE Red Magic 8 Pro <br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
28/02/2024

CVE-2023-50082

Publication date:
04/01/2024
Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via session leakage allows a user to avoid logging into the backend management platform.
Severity CVSS v4.0: Pending analysis
Last modification:
09/06/2025

CVE-2023-52322

Publication date:
04/01/2024
ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows XSS because input from _request() is not restricted to safe characters such as alphanumerics.
Severity CVSS v4.0: Pending analysis
Last modification:
03/06/2025

CVE-2022-43375

Publication date:
04/01/2024
Rejected reason: This CVE ID was unused by the CNA.
Severity CVSS v4.0: Pending analysis
Last modification:
04/01/2024

CVE-2023-29962

Publication date:
04/01/2024
S-CMS v5.0 was discovered to contain an arbitrary file read vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
03/06/2025

CVE-2023-6498

Publication date:
04/01/2024
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 6.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2026