Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-36120

Publication date:
18/07/2023
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-24390

Publication date:
18/07/2023
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WeSecur Security plugin
Severity CVSS v4.0: Pending analysis
Last modification:
27/07/2023

CVE-2022-47421

Publication date:
18/07/2023
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARMember (free), Repute InfoSystems ARMember (premium) plugins.
Severity CVSS v4.0: Pending analysis
Last modification:
27/07/2023

CVE-2023-31441

Publication date:
18/07/2023
In NATO Communications and Information Agency anet (aka Advisor Network) through 3.3.0, an attacker can provide a crafted JSON file to sanitizeJson and cause an exception. This is related to the U+FFFD Unicode replacement character. A for loop does not consider that a data structure is being modified during loop execution.
Severity CVSS v4.0: Pending analysis
Last modification:
27/07/2023

CVE-2020-36762

Publication date:
18/07/2023
A vulnerability was found in ONS Digital RAS Collection Instrument up to 2.0.27 and classified as critical. Affected by this issue is the function jobs of the file .github/workflows/comment.yml. The manipulation of the argument $COMMENT_BODY leads to os command injection. Upgrading to version 2.0.28 is able to address this issue. The name of the patch is dcaad2540f7d50c512ff2e031d3778dd9337db2b. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-234248.
Severity CVSS v4.0: Pending analysis
Last modification:
17/05/2024

CVE-2023-36384

Publication date:
18/07/2023
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodePeople Booking Calendar Contact Form plugin
Severity CVSS v4.0: Pending analysis
Last modification:
27/07/2023

CVE-2023-36383

Publication date:
18/07/2023
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin
Severity CVSS v4.0: Pending analysis
Last modification:
27/07/2023

CVE-2023-32965

Publication date:
18/07/2023
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CRUDLab Jazz Popups plugin
Severity CVSS v4.0: Pending analysis
Last modification:
27/07/2023

CVE-2022-41409

Publication date:
18/07/2023
Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.
Severity CVSS v4.0: Pending analysis
Last modification:
27/07/2023

CVE-2023-30906

Publication date:
18/07/2023
The vulnerability could be locally exploited to allow escalation of privilege.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
27/07/2023

CVE-2022-47085

Publication date:
18/07/2023
An issue was discovered in ostree before 2022.7 allows attackers to cause a denial of service or other unspecified impacts via the print_panic function in repo_checkout_filter.rs.
Severity CVSS v4.0: Pending analysis
Last modification:
20/12/2023

CVE-2022-34155

Publication date:
18/07/2023
Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
27/07/2023