Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-51653

Publication date:
19/11/2024
Cross-Site Request Forgery (CSRF) vulnerability in Mario Spinaci UPDATE NOTIFICATIONS allows Stored XSS.This issue affects UPDATE NOTIFICATIONS: from n/a through 0.3.4.
Severity CVSS v4.0: Pending analysis
Last modification:
19/11/2024

CVE-2024-51654

Publication date:
19/11/2024
Cross-Site Request Forgery (CSRF) vulnerability in APK.Support APK Downloader allows Stored XSS.This issue affects APK Downloader: from n/a through 1.0.0.
Severity CVSS v4.0: Pending analysis
Last modification:
19/11/2024

CVE-2024-51655

Publication date:
19/11/2024
Cross-Site Request Forgery (CSRF) vulnerability in Microkid Custom Author URL allows Stored XSS.This issue affects Custom Author URL: from n/a through 2.0.1.
Severity CVSS v4.0: Pending analysis
Last modification:
19/11/2024

CVE-2024-51656

Publication date:
19/11/2024
Cross-Site Request Forgery (CSRF) vulnerability in litefeel Flash Show And Hide Box allows Stored XSS.This issue affects Flash Show And Hide Box: from n/a through 1.6.
Severity CVSS v4.0: Pending analysis
Last modification:
19/11/2024

CVE-2024-51657

Publication date:
19/11/2024
Cross-Site Request Forgery (CSRF) vulnerability in Woopy Plugins SmartLink Dynamic URLs allows Stored XSS.This issue affects SmartLink Dynamic URLs: from n/a through 1.1.0.
Severity CVSS v4.0: Pending analysis
Last modification:
19/11/2024

CVE-2024-51648

Publication date:
19/11/2024
Cross-Site Request Forgery (CSRF) vulnerability in Hands, Inc e-shops allows Reflected XSS.This issue affects e-shops: from n/a through 1.0.3.
Severity CVSS v4.0: Pending analysis
Last modification:
19/11/2024

CVE-2024-51649

Publication date:
19/11/2024
Cross-Site Request Forgery (CSRF) vulnerability in Patrick Lumumba Mobilize allows Stored XSS.This issue affects Mobilize: from n/a through 3.0.7.
Severity CVSS v4.0: Pending analysis
Last modification:
19/11/2024

CVE-2024-51650

Publication date:
19/11/2024
Cross-Site Request Forgery (CSRF) vulnerability in Scott @ MyDollarPlan.com Random Featured Post allows Stored XSS.This issue affects Random Featured Post: from n/a through 1.1.3.
Severity CVSS v4.0: Pending analysis
Last modification:
19/11/2024

CVE-2024-51652

Publication date:
19/11/2024
Cross-Site Request Forgery (CSRF) vulnerability in Prem Nawaz Khan, Victor Tsaran, Ron Feathers, and Marc Kocher Skip To allows Stored XSS.This issue affects Skip To: from n/a through 2.0.0.
Severity CVSS v4.0: Pending analysis
Last modification:
19/11/2024

CVE-2024-51641

Publication date:
19/11/2024
Cross-Site Request Forgery (CSRF) vulnerability in jcmlmorav Advanced PDF Generator allows Stored XSS.This issue affects Advanced PDF Generator: from n/a through 0.4.0.
Severity CVSS v4.0: Pending analysis
Last modification:
19/11/2024

CVE-2024-51642

Publication date:
19/11/2024
Cross-Site Request Forgery (CSRF) vulnerability in webhostri Seo Free allows Stored XSS.This issue affects Seo Free: from n/a through 1.4.
Severity CVSS v4.0: Pending analysis
Last modification:
19/11/2024

CVE-2024-51643

Publication date:
19/11/2024
Cross-Site Request Forgery (CSRF) vulnerability in Rajan Agaskar Amazon Associate Filter allows Stored XSS.This issue affects Amazon Associate Filter: from n/a through 0.4.
Severity CVSS v4.0: Pending analysis
Last modification:
19/11/2024