Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-32457

Publication date:
29/08/2023
<br /> Dell PowerScale OneFS, versions 8.2.2.x-9.5.0.x, contains an improper privilege management vulnerability. A remote attacker with low privileges could potentially exploit this vulnerability, leading to escalation of privileges.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
20/02/2026

CVE-2023-41363

Publication date:
29/08/2023
In Cerebrate 1.14, a vulnerability in UserSettingsController allows authenticated users to change user settings of other users.
Severity CVSS v4.0: Pending analysis
Last modification:
31/08/2023

CVE-2023-41361

Publication date:
29/08/2023
An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.
Severity CVSS v4.0: Pending analysis
Last modification:
26/10/2023

CVE-2023-41359

Publication date:
29/08/2023
An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the availability of two bytes during AIGP validation.
Severity CVSS v4.0: Pending analysis
Last modification:
22/12/2023

CVE-2023-41358

Publication date:
29/08/2023
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
Severity CVSS v4.0: Pending analysis
Last modification:
22/12/2023

CVE-2023-41360

Publication date:
29/08/2023
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.
Severity CVSS v4.0: Pending analysis
Last modification:
16/10/2024

CVE-2023-1995

Publication date:
29/08/2023
Insufficient Logging vulnerability in Hitachi HiRDB Server, HiRDB Server With Addtional Function, HiRDB Structured Data Access Facility.This issue affects HiRDB Server: before 09-60-39, before 09-65-23, <br /> <br /> before 09-66-17, <br /> <br /> before 10-01-10, before 10-03-12, before 10-04-06, before 10-05-06, before 10-06-02; HiRDB Server With Addtional Function: before 09-60-2M, before 09-65-/W<br /> <br /> , before 09-66-/Q<br /> <br /> ; HiRDB Structured Data Access Facility: before 09-60-39, before 10-03-12, before 10-04-06, before 10-06-02.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
27/09/2023

CVE-2023-39650

Publication date:
28/08/2023
Theme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /tvcmsblog/single.
Severity CVSS v4.0: Pending analysis
Last modification:
31/08/2023

CVE-2023-40998

Publication date:
28/08/2023
Buffer Overflow vulnerability in O-RAN Software Community ric-plt-lib-rmr v.4.9.0 allows a remote attacker to cause a denial of service via the packet size component.
Severity CVSS v4.0: Pending analysis
Last modification:
14/12/2023

CVE-2023-40997

Publication date:
28/08/2023
Buffer Overflow vulnerability in O-RAN Software Community ric-plt-lib-rmr v.4.9.0 allows a remote attacker to cause a denial of service via a crafted packet.
Severity CVSS v4.0: Pending analysis
Last modification:
14/12/2023

CVE-2023-41005

Publication date:
28/08/2023
An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateAction functions in UpdateController.php
Severity CVSS v4.0: Pending analysis
Last modification:
02/10/2024

CVE-2023-4569

Publication date:
28/08/2023
A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux Kernel. This issue may allow a local attacker to cause double-deactivations of catchall elements, which can result in a memory leak.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023