Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-44015

Publication date:
27/09/2023
Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the schedEndTime parameter in the setSchedWifi function.
Severity CVSS v4.0: Pending analysis
Last modification:
25/09/2024

CVE-2023-43493

Publication date:
27/09/2023
SQL injection vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with author or higher privilege to obtain sensitive information.
Severity CVSS v4.0: Pending analysis
Last modification:
20/02/2025

CVE-2023-43610

Publication date:
27/09/2023
SQL injection vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor (without setting authority) or higher privilege to perform unintended database operations.
Severity CVSS v4.0: Pending analysis
Last modification:
20/02/2025

CVE-2023-43331

Publication date:
27/09/2023
A cross-site scripting (XSS) vulnerability in the Add User function of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Severity CVSS v4.0: Pending analysis
Last modification:
29/09/2023

CVE-2023-43828

Publication date:
27/09/2023
A Cross-site scripting (XSS) vulnerability in /panel/languages/ of Subrion v4.2.1 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into 'Title' parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
28/09/2023

CVE-2023-43830

Publication date:
27/09/2023
A Cross-site scripting (XSS) vulnerability in /panel/configuration/financial/ of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into several fields: 'Minimum deposit', 'Maximum deposit' and/or 'Maximum balance'.
Severity CVSS v4.0: Pending analysis
Last modification:
28/09/2023

CVE-2023-43645

Publication date:
27/09/2023
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA is vulnerable to a denial of service attack when certain Check calls are executed against authorization models that contain circular relationship definitions. When the call is made, it's possible for the server to exhaust resources and die. Users are advised to upgrade to v1.3.2 and update any offending models. There are no known workarounds for this vulnerability. Note that for models which contained cycles or a relation definition that has the relation itself in its evaluation path, checks and queries that require evaluation will no longer be evaluated on v1.3.2+ and will return errors instead. Users who do not have cyclic models are unaffected.
Severity CVSS v4.0: Pending analysis
Last modification:
02/10/2023

CVE-2023-43825

Publication date:
27/09/2023
Relative path traversal vulnerability in Shihonkanri Plus Ver9.0.3 and earlier allows a local attacker to execute an arbitrary code by having a legitimate user import a specially crafted backup file of the product..
Severity CVSS v4.0: Pending analysis
Last modification:
02/10/2023

CVE-2023-43484

Publication date:
27/09/2023
Cross-site scripting vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.
Severity CVSS v4.0: Pending analysis
Last modification:
20/02/2025

CVE-2023-43614

Publication date:
27/09/2023
Cross-site scripting vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.
Severity CVSS v4.0: Pending analysis
Last modification:
20/02/2025

CVE-2023-43775

Publication date:
27/09/2023
Denial-of-service vulnerability in the web server of the Eaton SMP Gateway allows <br /> <br /> attacker to potentially force an unexpected restart of the automation platform, impacting the availability of the product. In rare situations, the issue could cause<br /> the SMP device to restart in Safe Mode or Max Safe Mode. When in Max Safe Mode, the product is<br /> not vulnerable anymore.<br />
Severity CVSS v4.0: Pending analysis
Last modification:
02/10/2023

CVE-2023-43856

Publication date:
27/09/2023
Dreamer CMS v4.1.3 was discovered to contain an arbitrary file read vulnerability via the component /admin/TemplateController.java.
Severity CVSS v4.0: Pending analysis
Last modification:
04/04/2025