Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-26114

Publication date:
23/03/2023
Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.
Severity CVSS v4.0: Pending analysis
Last modification:
25/02/2025

CVE-2023-28759

Publication date:
23/03/2023
An issue was discovered in Veritas NetBackup before 10.0 on Windows. A vulnerability in the way the client validates the path to a DLL prior to loading may allow a lower-level user to elevate privileges and compromise the system.
Severity CVSS v4.0: Pending analysis
Last modification:
25/02/2025

CVE-2023-28758

Publication date:
23/03/2023
An issue was discovered in Veritas NetBackup before 8.3.0.2. BPCD allows an unprivileged user to specify a log file path when executing a NetBackup command. This can be used to overwrite existing NetBackup log files.
Severity CVSS v4.0: Pending analysis
Last modification:
25/02/2025

CVE-2023-23192

Publication date:
23/03/2023
IS Decisions UserLock MFA 11.01 is vulnerable to authentication bypass using scheduled task.
Severity CVSS v4.0: Pending analysis
Last modification:
27/03/2023

CVE-2023-27249

Publication date:
23/03/2023
swfdump v0.9.2 was discovered to contain a heap buffer overflow in the function swf_GetPlaceObject at swfobject.c.
Severity CVSS v4.0: Pending analysis
Last modification:
25/02/2025

CVE-2023-26496

Publication date:
23/03/2023
An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T5124. Memory corruption can occur due to improper checking of the parameter length while parsing the fmtp attribute in the SDP (Session Description Protocol) module.
Severity CVSS v4.0: Pending analysis
Last modification:
24/03/2023

CVE-2022-30037

Publication date:
23/03/2023
XunRuiCMS v4.3.3 to v4.5.1 vulnerable to PHP file write and CMS PHP file inclusion, allows attackers to execute arbitrary php code, via the add function in cron.php.
Severity CVSS v4.0: Pending analysis
Last modification:
28/03/2023

CVE-2023-24367

Publication date:
23/03/2023
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-26498

Publication date:
23/03/2023
An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos Auto T5126. Memory corruption can occur due to improper checking of the number of properties while parsing the chatroom attribute in the SDP (Session Description Protocol) module.
Severity CVSS v4.0: Pending analysis
Last modification:
24/03/2023

CVE-2023-24655

Publication date:
23/03/2023
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Profile Update function.
Severity CVSS v4.0: Pending analysis
Last modification:
27/06/2025

CVE-2023-26088

Publication date:
23/03/2023
In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine system. It can also lead to privilege escalation in certain scenarios.
Severity CVSS v4.0: Pending analysis
Last modification:
28/03/2023

CVE-2023-28470

Publication date:
23/03/2023
In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.
Severity CVSS v4.0: Pending analysis
Last modification:
24/02/2025