Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-34575

Publication date:
02/08/2021
In MB connect line mymbCONNECT24, mbCONNECT24 in versions
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2021

CVE-2021-33526

Publication date:
02/08/2021
In MB connect line mbDIALUP versions
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2021

CVE-2021-24504

Publication date:
02/08/2021
The WP LMS – Best WordPress LMS Plugin WordPress plugin through 1.1.2 does not properly sanitise or validate its User Field Titles, allowing XSS payload to be used in them. Furthermore, no CSRF and capability checks were in place, allowing such attack to be performed either via CSRF or as any user (including unauthenticated)
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2021-24474

Publication date:
02/08/2021
The Awesome Weather Widget WordPress plugin through 3.0.2 does not sanitize the id parameter of its awesome_weather_refresh AJAX action, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) Vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
10/11/2021

CVE-2021-24476

Publication date:
02/08/2021
The Steam Group Viewer WordPress plugin through 2.1 does not sanitise or escape its "Steam Group Address" settings before outputting it in the page, leading to an authenticated Stored Cross-Site Scripting issue
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2021

CVE-2021-24481

Publication date:
02/08/2021
The Any Hostname WordPress plugin through 1.0.6 does not sanitise or escape its "Allowed hosts" setting, leading to an authenticated stored XSS issue as high privilege users are able to set XSS payloads in it
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2021

CVE-2021-24496

Publication date:
02/08/2021
The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2021

CVE-2021-24492

Publication date:
02/08/2021
The hndtst_action_instance_callback AJAX call of the Handsome Testimonials & Reviews WordPress plugin before 2.1.1, available to any authenticated users, does not sanitise, validate or escape the hndtst_previewShortcodeInstanceId POST parameter before using it in a SQL statement, leading to an SQL Injection issue.
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2021

CVE-2021-24483

Publication date:
02/08/2021
The get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker WordPress plugin before 3.2.1 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2021

CVE-2021-24484

Publication date:
02/08/2021
The get_reports() function in the Secure Copy Content Protection and Content Locking WordPress plugin before 2.6.7 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2021

CVE-2021-24488

Publication date:
02/08/2021
The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2021

CVE-2021-24480

Publication date:
02/08/2021
The Event Geek WordPress plugin through 2.5.2 does not sanitise or escape its "Use your own " setting before outputting it in the page, leading to an authenticated (admin+) stored Cross-Site Scripting issue
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2021