Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-4040

Publication date:
18/08/2023
The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eh_callback_handler function in versions up to, and including, 3.7.9. This makes it possible for unauthenticated attackers to modify the order status of arbitrary WooCommerce orders.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-39674

Publication date:
18/08/2023
D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function fgets.
Severity CVSS v4.0: Pending analysis
Last modification:
25/08/2023

CVE-2023-39673

Publication date:
18/08/2023
Tenda AC15 V1.0BR_V15.03.05.18_multi_TD01 was discovered to contain a buffer overflow via the function FUN_00010e34().
Severity CVSS v4.0: Pending analysis
Last modification:
23/08/2023

CVE-2023-39672

Publication date:
18/08/2023
Tenda WH450 v1.0.0.18 was discovered to contain a buffer overflow via the function fgets.
Severity CVSS v4.0: Pending analysis
Last modification:
23/08/2023

CVE-2023-39671

Publication date:
18/08/2023
D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function FUN_0001be68.
Severity CVSS v4.0: Pending analysis
Last modification:
25/08/2023

CVE-2023-39667

Publication date:
18/08/2023
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the FUN_0000acb4 function.
Severity CVSS v4.0: Pending analysis
Last modification:
02/08/2024

CVE-2023-39669

Publication date:
18/08/2023
D-Link DIR-880 A1_FW107WWb08 was discovered to contain a NULL pointer dereference in the function FUN_00010824.
Severity CVSS v4.0: Pending analysis
Last modification:
25/08/2023

CVE-2023-39668

Publication date:
18/08/2023
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the inet_ntoa() function.
Severity CVSS v4.0: Pending analysis
Last modification:
02/08/2024

CVE-2023-39670

Publication date:
18/08/2023
Tenda AC6 _US_AC6V1.0BR_V15.03.05.16 was discovered to contain a buffer overflow via the function fgets.
Severity CVSS v4.0: Pending analysis
Last modification:
23/08/2023

CVE-2023-39665

Publication date:
18/08/2023
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the acStack_50 parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
02/08/2024

CVE-2023-39666

Publication date:
18/08/2023
D-Link DIR-842 fw_revA_1-02_eu_multi_20151008 was discovered to contain multiple buffer overflows in the fgets function via the acStack_120 and acStack_220 parameters.
Severity CVSS v4.0: Pending analysis
Last modification:
25/08/2023

CVE-2023-39125

Publication date:
18/08/2023
NTSC-CRT 2.2.1 has an integer overflow and out-of-bounds write in loadBMP in bmp_rw.c because a file's width, height, and BPP are not validated. NOTE: the vendor's perspective is "this main application was not intended to be a well tested program, it's just something to demonstrate it works and for the user to see how to integrate it into their own programs."
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2023