Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-20969

Publication date:
20/06/2023
File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.
Severity CVSS v4.0: Pending analysis
Last modification:
16/04/2025

CVE-2020-20919

Publication date:
20/06/2023
File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the theme.php file.
Severity CVSS v4.0: Pending analysis
Last modification:
10/12/2024

CVE-2020-20735

Publication date:
20/06/2023
File Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
10/12/2024

CVE-2020-20726

Publication date:
20/06/2023
Cross Site Request Forgery vulnerability in Gila GilaCMS v.1.11.4 allows a remote attacker to execute arbitrary code via the cm/update_rows/user parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
11/12/2024

CVE-2020-20725

Publication date:
20/06/2023
Cross Site Scripting vulnerability in taogogo taoCMS v.2.5 beta5.1 allows remote attacker to execute arbitrary code via the name field in admin.php.
Severity CVSS v4.0: Pending analysis
Last modification:
11/12/2024

CVE-2020-20718

Publication date:
20/06/2023
File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to the the save_file() parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
10/12/2024

CVE-2023-35095

Publication date:
20/06/2023
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Flothemes Flo Forms – Easy Drag & Drop Form Builder plugin
Severity CVSS v4.0: Pending analysis
Last modification:
27/06/2023

CVE-2023-34597

Publication date:
20/06/2023
A vulnerability in Fibaro Motion Sensor firmware v3.4 allows attackers to cause a Denial of Service (DoS) via a crafted Z-Wave message.
Severity CVSS v4.0: Pending analysis
Last modification:
09/12/2024

CVE-2023-33495

Publication date:
20/06/2023
Craft CMS through 4.4.9 is vulnerable to HTML Injection.
Severity CVSS v4.0: Pending analysis
Last modification:
09/12/2024

CVE-2023-34596

Publication date:
20/06/2023
A vulnerability in Aeotec WallMote Switch firmware v2.3 allows attackers to cause a Denial of Service (DoS) via a crafted Z-Wave message.
Severity CVSS v4.0: Pending analysis
Last modification:
09/12/2024

CVE-2023-1999

Publication date:
20/06/2023
There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.
Severity CVSS v4.0: Pending analysis
Last modification:
13/02/2025

CVE-2023-3337

Publication date:
20/06/2023
A vulnerability was found in PuneethReddyHC Online Shopping System Advanced 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/reg.php of the component Admin Registration. The manipulation leads to improper authentication. The attack can be launched remotely. The identifier VDB-232009 was assigned to this vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
17/05/2024