Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-34842

Publication date:
31/07/2023
Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2023

CVE-2023-34635

Publication date:
31/07/2023
Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or sanitizing the user input in the username field of the login page.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2023

CVE-2023-34644

Publication date:
31/07/2023
Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204, RG-NBS and RG-S1930 series switches SWITCH_3.0(1)B11P218, RG-EG series business VPN routers EG_3.0(1)B11P216, EAP and RAP series wireless access points AP_3.0(1)B11P218, NBC series wireless controllers AC_3.0(1)B11P86 allows unauthorized remote attackers to gain the highest privileges via crafted POST request to /cgi-bin/luci/api/auth.
Severity CVSS v4.0: Pending analysis
Last modification:
14/05/2024

CVE-2023-34872

Publication date:
31/07/2023
A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.
Severity CVSS v4.0: Pending analysis
Last modification:
04/11/2025

CVE-2020-21662

Publication date:
31/07/2023
SQL injection vulnerability in yunyecms 2.0.2 allows remote attackers to run arbitrary SQL commands via XFF.
Severity CVSS v4.0: Pending analysis
Last modification:
03/08/2023

CVE-2020-21881

Publication date:
31/07/2023
Cross Site Request Forgery (CSRF) vulnerability in admin.php in DuxCMS 2.1 allows remote attackers to modtify application data via article/admin/content/add.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2023

CVE-2023-37647

Publication date:
31/07/2023
SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2023

CVE-2023-35861

Publication date:
31/07/2023
A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC.
Severity CVSS v4.0: Pending analysis
Last modification:
07/08/2023

CVE-2023-3508

Publication date:
31/07/2023
The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when processing its tab actions, which could allow attackers to make logged in admins email pre-orders customer, change the released date, mark all pre-orders of a specific product as complete or cancel via CSRF attacks
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2025

CVE-2023-3507

Publication date:
31/07/2023
The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when canceling pre-orders, which could allow attackers to make logged in admins cancel arbitrary pre-orders via a CSRF attack
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2025

CVE-2023-3345

Publication date:
31/07/2023
The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students
Severity CVSS v4.0: Pending analysis
Last modification:
10/06/2025

CVE-2023-0602

Publication date:
31/07/2023
The Twittee Text Tweet WordPress plugin through 1.0.8 does not properly escape POST values which are printed back to the user inside one of the plugin's administrative page, which allows reflected XSS attacks targeting administrators to happen.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023