Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-21861

Publication date:
06/07/2023
File upload vulnerability in DuxCMS 2.1 allows attackers to execute arbitrary php code via duxcms/AdminUpload/upload.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2023

CVE-2020-21862

Publication date:
06/07/2023
Directory traversal vulnerability in DuxCMS 2.1 allows attackers to delete arbitrary files via /admin/AdminBackup/del.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2023

CVE-2021-46896

Publication date:
06/07/2023
Buffer Overflow vulnerability in PX4-Autopilot allows attackers to cause a denial of service via handler function handling msgid 332.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2023

CVE-2023-35937

Publication date:
06/07/2023
Metersphere is an open source continuous testing platform. In versions prior to 2.10.2 LTS, some key APIs in Metersphere lack permission checks. This allows ordinary users to execute APIs that can only be executed by space administrators or project administrators. For example, ordinary users can be updated as space administrators. Version 2.10.2 LTS has a patch for this issue.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2023

CVE-2023-36188

Publication date:
06/07/2023
An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Python exec method.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2023

CVE-2023-36189

Publication date:
06/07/2023
SQL injection vulnerability in langchain before v0.0.247 allows a remote attacker to obtain sensitive information via the SQLDatabaseChain component.
Severity CVSS v4.0: Pending analysis
Last modification:
15/10/2024

CVE-2023-36995

Publication date:
06/07/2023
TravianZ through 8.3.4 allows XSS via the Alliance tag/name, the statistics page, the link preferences, the Admin Logs, or the COOKUSR cookie.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2023

CVE-2023-36968

Publication date:
06/07/2023
A SQL Injection vulnerability detected in Food Ordering System v1.0 allows attackers to run commands on the database by sending crafted SQL queries to the ID parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
10/07/2023

CVE-2020-22336

Publication date:
06/07/2023
An issue was discovered in pdfcrack 0.17 thru 0.18, allows attackers to execute arbitrary code via a stack overflow in the MD5 function.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2023

CVE-2023-37242

Publication date:
06/07/2023
Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite the non-volatile random-access memory (NVRAM), or facilitate the exploitation of other vulnerabilities.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2023

CVE-2023-37245

Publication date:
06/07/2023
Buffer overflow vulnerability in the modem pinctrl module. Successful exploitation of this vulnerability may affect the integrity and availability of the modem.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2023

CVE-2023-3456

Publication date:
06/07/2023
Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability may affect service confidentiality.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2023