Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-11999

Publication date:
17/12/2024
CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete<br /> control of the device when an authenticated user installs malicious code into HMI product.
Severity CVSS v4.0: HIGH
Last modification:
17/12/2024

CVE-2021-26280

Publication date:
17/12/2024
Locally installed application can bypass the permission check and perform system operations that require permission.
Severity CVSS v4.0: Pending analysis
Last modification:
17/12/2024

CVE-2021-26281

Publication date:
17/12/2024
Some parameters of the alarm clock module are improperly stored, leaking some sensitive information.
Severity CVSS v4.0: Pending analysis
Last modification:
17/12/2024

CVE-2024-54125

Publication date:
17/12/2024
Improper authorization in handler for custom URL scheme issue in "Shonen Jump+" App for Android versions prior to 4.0.0 allows an attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.
Severity CVSS v4.0: Pending analysis
Last modification:
17/12/2024

CVE-2024-9624

Publication date:
17/12/2024
The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.9.3 due to missing SSRF protection on the pmxi_curl_download function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. On cloud platforms, it might allow attackers to read the Instance metadata.
Severity CVSS v4.0: Pending analysis
Last modification:
17/12/2024

CVE-2024-38499

Publication date:
17/12/2024
CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryption keys which further causes the exploitation of stored credentials. This fix doesn&amp;#39;t allow a non-admin/non-root user to execute "caf encrypt"/"sd_acmd encrypt" commands.
Severity CVSS v4.0: HIGH
Last modification:
19/12/2024

CVE-2024-55864

Publication date:
17/12/2024
Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious administrative user customizes the administrative page with some malicious contents, an arbitrary script may be executed on the web browser of the other users who are accessing the page.
Severity CVSS v4.0: Pending analysis
Last modification:
17/12/2024

CVE-2024-12356

Publication date:
17/12/2024
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
Severity CVSS v4.0: Pending analysis
Last modification:
24/10/2025

CVE-2021-26279

Publication date:
17/12/2024
Some parameters of the weather module are improperly stored, leaking some sensitive information.
Severity CVSS v4.0: Pending analysis
Last modification:
17/12/2024

CVE-2020-12487

Publication date:
17/12/2024
Due to the flaws in the verification of input parameters, the attacker can input carefully constructed commands to make the ABE service execute some commands with root privilege.
Severity CVSS v4.0: Pending analysis
Last modification:
17/12/2024

CVE-2021-26278

Publication date:
17/12/2024
The wifi module exposes the interface and has improper permission control, leaking sensitive information about the device.
Severity CVSS v4.0: Pending analysis
Last modification:
17/12/2024

CVE-2024-12239

Publication date:
17/12/2024
The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the navigate parameter in all versions up to, and including, 1.3.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick an administrative user into performing an action such as clicking on a link.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2025