Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-49904

Publication date:
28/05/2025
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2025

CVE-2023-50338

Publication date:
28/05/2025
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2025

CVE-2023-51753

Publication date:
28/05/2025
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2025

CVE-2023-51756

Publication date:
28/05/2025
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2025

CVE-2023-48726

Publication date:
28/05/2025
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2025

CVE-2025-27702

Publication date:
28/05/2025
CVE-2025-27702 is a vulnerability in the management console of Absolute <br /> Secure Access prior to version 13.54. Attackers with administrative <br /> access to the console and who have been assigned a certain set of <br /> permissions can bypass those permissions to improperly modify settings. <br /> The attack complexity is low, there are no preexisting attack <br /> requirements; the privileges required are high, and there is no user <br /> interaction required. There is no impact to system confidentiality or <br /> availability, impact to system integrity is high.
Severity CVSS v4.0: MEDIUM
Last modification:
04/06/2025

CVE-2025-27703

Publication date:
28/05/2025
CVE-2025-27703 is a privilege escalation vulnerability in the management<br /> console of Absolute Secure Access prior to version 13.54. Attackers <br /> with administrative access to a specific subset of privileged features <br /> in the console can elevate their permissions to access additional <br /> features in the console. The attack complexity is low, there are no <br /> preexisting attack requirements; the privileges required are high, and <br /> there is no user interaction required. The impact to system <br /> confidentiality is low, the impact to system integrity is high and the <br /> impact to system availability is low.
Severity CVSS v4.0: HIGH
Last modification:
04/06/2025

CVE-2025-27706

Publication date:
28/05/2025
CVE-2025-27706 is a cross-site scripting vulnerability in the management<br /> console of Absolute Secure Access prior to version 13.54. Attackers <br /> with system administrator permissions can interfere with another system <br /> administrator’s use of the management console when the second <br /> administrator visits the page. Attack complexity is low, there are no <br /> preexisting attack requirements, privileges required are high and active<br /> user interaction is required. There is no impact on confidentiality, <br /> the impact on integrity is low and there is no impact on availability.
Severity CVSS v4.0: MEDIUM
Last modification:
04/06/2025

CVE-2022-46735

Publication date:
28/05/2025
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2025

CVE-2022-46736

Publication date:
28/05/2025
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2025

CVE-2022-46739

Publication date:
28/05/2025
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2025

CVE-2022-47914

Publication date:
28/05/2025
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2025