Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-30199

Publication date:
19/05/2023
Prestashop customexporter
Severity CVSS v4.0: Pending analysis
Last modification:
21/01/2025

CVE-2023-31707

Publication date:
19/05/2023
SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.
Severity CVSS v4.0: Pending analysis
Last modification:
21/01/2025

CVE-2023-31757

Publication date:
19/05/2023
DedeCMS up to v5.7.108 is vulnerable to XSS in sys_info.php via parameters 'edit___cfg_powerby' and 'edit___cfg_beian'
Severity CVSS v4.0: Pending analysis
Last modification:
21/01/2025

CVE-2023-31862

Publication date:
19/05/2023
jizhicms v2.4.6 is vulnerable to Cross Site Scripting (XSS). The content of the article published in the front end is only filtered in the front end, without being filtered in the background, which allows attackers to publish an article containing malicious JavaScript scripts by modifying the request package.
Severity CVSS v4.0: Pending analysis
Last modification:
21/01/2025

CVE-2023-31756

Publication date:
19/05/2023
A command injection vulnerability exists in the administrative web portal in TP-Link Archer VR1600V devices running firmware Versions
Severity CVSS v4.0: Pending analysis
Last modification:
21/01/2025

CVE-2022-30114

Publication date:
19/05/2023
A heap-based buffer overflow in a network service in Fastweb FASTGate MediaAccess FGA2130FWB, firmware version 18.3.n.0482_FW_230_FGA2130, and DGA4131FWB, firmware version up to 18.3.n.0462_FW_261_DGA4131, allows a remote attacker to reboot the device through a crafted HTTP request, causing DoS.
Severity CVSS v4.0: Pending analysis
Last modification:
21/01/2025

CVE-2023-26818

Publication date:
19/05/2023
Telegram 9.3.1 and 9.4.0 allows attackers to access restricted files, microphone ,or video recording via the DYLD_INSERT_LIBRARIES flag.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2023-2806

Publication date:
19/05/2023
A vulnerability classified as problematic was found in Weaver e-cology up to 9.0. Affected by this vulnerability is the function RequestInfoByXml of the component API. The manipulation leads to xml external entity reference. The associated identifier of this vulnerability is VDB-229411. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity CVSS v4.0: Pending analysis
Last modification:
17/05/2024

CVE-2023-28045

Publication date:
19/05/2023
<br /> Dell CloudIQ Collector version 1.10.2 contains a missing encryption of sensitive data vulnerability. An attacker with low privileges could potentially exploit this vulnerability, leading to gain access to unauthorized data.
Severity CVSS v4.0: Pending analysis
Last modification:
07/08/2026

CVE-2023-33240

Publication date:
19/05/2023
Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x versions, 11.2.5.53785 and all previous 11.x versions, and 10.1.11.37866 and earlier) on Windows allows Local Privilege Escalation when installed to a non-default directory because unprivileged users have access to an executable file of a system service. This is fixed in 12.1.2.
Severity CVSS v4.0: Pending analysis
Last modification:
21/01/2025

CVE-2023-1618

Publication date:
19/05/2023
Active Debug Code vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 Serial number 2310 **** and prior allows a remote unauthenticated attacker to bypass authentication and illegally log into the affected module by connecting to it via telnet which is hidden function and is enabled by default when shipped from the factory. As a result, a remote attacker with unauthorized login can reset the module, and if certain conditions are met, he/she can disclose or tamper with the module&amp;#39;s configuration or rewrite the firmware.
Severity CVSS v4.0: Pending analysis
Last modification:
23/08/2023

CVE-2023-2704

Publication date:
19/05/2023
The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2026