Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-2807

Publication date:
02/12/2022
SQL Injection vulnerability in Algan Software Prens Student Information System allows SQL Injection.This issue affects Prens Student Information System: before 2.1.11.
Severity CVSS v4.0: Pending analysis
Last modification:
17/09/2024

CVE-2022-2808

Publication date:
02/12/2022
Authorization Bypass Through User-Controlled Key vulnerability in Algan Software Prens Student Information System allows Object Relational Mapping Injection.This issue affects Prens Student Information System: before 2.1.11.
Severity CVSS v4.0: Pending analysis
Last modification:
16/09/2024

CVE-2022-45562

Publication date:
02/12/2022
Insecure permissions in Telos Alliance Omnia MPX Node v1.0.0 to v1.4.9 allow attackers to manipulate and access system settings with backdoor account low privilege, this can lead to change hardware settings and execute arbitrary commands in vulnerable system functions that is requires high privilege to access.
Severity CVSS v4.0: Pending analysis
Last modification:
24/04/2025

CVE-2022-44929

Publication date:
02/12/2022
An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles.
Severity CVSS v4.0: Pending analysis
Last modification:
24/04/2025

CVE-2022-44930

Publication date:
02/12/2022
D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function.
Severity CVSS v4.0: Pending analysis
Last modification:
24/04/2025

CVE-2022-43325

Publication date:
02/12/2022
An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows attackers to execute arbitrary commands via a crafted payload injected into the license input.
Severity CVSS v4.0: Pending analysis
Last modification:
24/04/2025

CVE-2022-44928

Publication date:
02/12/2022
D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.
Severity CVSS v4.0: Pending analysis
Last modification:
24/04/2025

CVE-2022-43333

Publication date:
01/12/2022
Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the component action_export_control.php.
Severity CVSS v4.0: Pending analysis
Last modification:
24/04/2025

CVE-2022-44212

Publication date:
01/12/2022
In GL.iNet Goodcloud 1.0, insecure design allows remote attacker to access devices' admin panel.
Severity CVSS v4.0: Pending analysis
Last modification:
24/04/2025

CVE-2022-44211

Publication date:
01/12/2022
In GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings.
Severity CVSS v4.0: Pending analysis
Last modification:
24/04/2025

CVE-2022-35120

Publication date:
01/12/2022
IXPdata EasyInstall 6.6.14725 contains an access control issue.
Severity CVSS v4.0: Pending analysis
Last modification:
24/04/2025

CVE-2022-23737

Publication date:
01/12/2022
An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improper privileges to create or delete pages via the API. To exploit this vulnerability, an attacker would need to be added to an organization's repo with write permissions. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.7 and was fixed in versions 3.2.20, 3.3.15, 3.4.10, 3.5.7, and 3.6.3. This vulnerability was reported via the GitHub Bug Bounty program.
Severity CVSS v4.0: Pending analysis
Last modification:
24/04/2025