Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-3466

Publication date:
15/09/2023
The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing the fix for CVE-2022-27652, which was previously fixed in OCP 4.9.41 and 4.10.12 via RHBA-2022:5433 and RHSA-2022:1600. This issue could allow an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. For more details, see https://access.redhat.com/security/cve/CVE-2022-27652.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-4959

Publication date:
15/09/2023
A flaw was found in Quay. Cross-site request forgery (CSRF) attacks force a user to perform unwanted actions in an application. During the pentest, it was detected that the config-editor page is vulnerable to CSRF. The config-editor page is used to configure the Quay instance. By coercing the victim’s browser into sending an attacker-controlled request from another domain, it is possible to reconfigure the Quay instance (including adding users with admin privileges).
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-4662

Publication date:
15/09/2023
Execution with Unnecessary Privileges vulnerability in Saphira Saphira Connect allows Remote Code Inclusion.This issue affects Saphira Connect: before 9.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
24/09/2025

CVE-2023-4664

Publication date:
15/09/2023
Incorrect Default Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation.This issue affects Saphira Connect: before 9.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
24/09/2025

CVE-2023-4665

Publication date:
15/09/2023
Incorrect Execution-Assigned Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation.This issue affects Saphira Connect: before 9.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
24/09/2025

CVE-2023-4833

Publication date:
15/09/2023
Improper Neutralization of Special Elements used in an SQL Command (&amp;#39;SQL Injection&amp;#39;) vulnerability in Besttem Network Marketing Software allows SQL Injection.This issue affects Network Marketing Software: before 1.0.2309.6.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
20/09/2023

CVE-2023-4835

Publication date:
15/09/2023
Improper Neutralization of Special Elements used in an SQL Command (&amp;#39;SQL Injection&amp;#39;) vulnerability in CF Software Oil Management Software allows SQL Injection.This issue affects Oil Management Software: before 20230912 .<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
20/09/2023

CVE-2023-4663

Publication date:
15/09/2023
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Saphira Saphira Connect allows Reflected XSS.This issue affects Saphira Connect: before 9.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
24/09/2025

CVE-2023-4661

Publication date:
15/09/2023
Improper Neutralization of Special Elements used in an SQL Command (&amp;#39;SQL Injection&amp;#39;) vulnerability in Saphira Saphira Connect allows SQL Injection.This issue affects Saphira Connect: before 9.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
24/09/2025

CVE-2023-4831

Publication date:
15/09/2023
Improper Neutralization of Special Elements used in an SQL Command (&amp;#39;SQL Injection&amp;#39;) vulnerability in Ncode Ncep allows SQL Injection.This issue affects Ncep: before 20230914 .<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
20/09/2023

CVE-2023-4670

Publication date:
15/09/2023
Improper Neutralization of Special Elements used in an SQL Command (&amp;#39;SQL Injection&amp;#39;) vulnerability in Innosa Probbys allows SQL Injection.This issue affects Probbys: before 2.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
20/09/2023

CVE-2023-4231

Publication date:
15/09/2023
Improper Neutralization of Special Elements used in an SQL Command (&amp;#39;SQL Injection&amp;#39;) vulnerability in Cevik Informatics Online Payment System allows SQL Injection.This issue affects Online Payment System: before 4.09.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
20/09/2023