Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-39986

Publication date:
01/08/2023
A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-37478

Publication date:
01/08/2023
pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed via pnpm is malicious, due to how pnpm parses tar archives. This can result in a package that appears safe on the npm registry or when installed via npm being replaced with a compromised or malicious version when installed via pnpm. This issue has been patched in version(s) 7.33.4 and 8.6.8.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2023

CVE-2023-32302

Publication date:
01/08/2023
Rejected reason: Authoritative user requested CVE rejection<br /> https://github.com/github/advisory-database/pull/2575#issuecomment-1745811653
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-23548

Publication date:
01/08/2023
Reflected XSS in business intelligence in Checkmk
Severity CVSS v4.0: Pending analysis
Last modification:
23/07/2024

CVE-2023-26139

Publication date:
01/08/2023
Versions of the package underscore-keypath from 0.0.11 are vulnerable to Prototype Pollution via the name argument of the setProperty() function. Exploiting this vulnerability is possible due to improper input sanitization which allows the usage of arguments like “__proto__”.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-34960

Publication date:
01/08/2023
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2023

CVE-2023-36983

Publication date:
01/08/2023
LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2023

CVE-2023-36984

Publication date:
01/08/2023
LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2023

CVE-2020-10962

Publication date:
01/08/2023
In PowerShell App Deployment Toolkit (aka PSAppDeployToolkit) through 3.8.0, an incorrect access control vulnerability in the default configuration may allow an authenticated user to potentially enable escalation of privilege via local access.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2023

CVE-2023-4033

Publication date:
01/08/2023
OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2023

CVE-2023-37772

Publication date:
01/08/2023
Online Shopping Portal Project v3.1 was discovered to contain a SQL injection vulnerability via the Email parameter at /shopping/login.php.
Severity CVSS v4.0: Pending analysis
Last modification:
14/11/2023

CVE-2023-37496

Publication date:
01/08/2023
HCL Verse is susceptible to a Stored Cross Site Scripting (XSS) vulnerability. An attacker could execute script in a victim&amp;#39;s web browser to perform operations as the victim and/or steal the victim&amp;#39;s cookies, session tokens, or other sensitive information.<br />
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2023