Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-36984

Publication date:
01/07/2024
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they could then use to serialize untrusted data. The attacker could use the query to execute arbitrary code.
Severity CVSS v4.0: Pending analysis
Last modification:
07/03/2025

CVE-2024-36985

Publication date:
01/07/2024
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or power Splunk roles could cause a Remote Code Execution through an external lookup that references the “splunk_archiver“ application.
Severity CVSS v4.0: Pending analysis
Last modification:
07/03/2025

CVE-2024-36986

Publication date:
01/07/2024
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, an authenticated user could run risky commands using the permissions of a higher-privileged user to bypass SPL safeguards for risky commands in the Analytics Workspace. The vulnerability requires the authenticated user to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will.
Severity CVSS v4.0: Pending analysis
Last modification:
02/08/2024

CVE-2024-21586

Publication date:
01/07/2024
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series and NFX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).<br /> <br /> If an affected device receives specific valid traffic destined to the device, it will cause the PFE to crash and restart. Continued receipt and processing of this traffic will create a sustained DoS condition.<br /> <br /> This issue affects Junos OS on SRX Series:<br /> <br /> * 21.4 versions before 21.4R3-S7.9,<br /> * 22.1 versions before 22.1R3-S5.3,<br /> * 22.2 versions before 22.2R3-S4.11,<br /> * 22.3 versions before 22.3R3,<br /> * 22.4 versions before 22.4R3.<br /> <br /> <br /> <br /> <br /> <br /> <br /> This issue affects Junos OS on NFX Series:<br /> <br /> * 21.4 versions before 21.4R3-S8,<br /> * 22.1 versions after 22.1R1,<br /> * 22.2 versions before 22.2R3-S5,<br /> * 22.3 versions before 22.3R3,<br /> * 22.4 versions before 22.4R3.<br /> <br /> <br /> <br /> <br /> <br /> <br /> Junos OS versions prior to 21.4R1 are not affected by this issue.
Severity CVSS v4.0: Pending analysis
Last modification:
22/01/2026

CVE-2024-20399

Publication date:
01/07/2024
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device.<br /> <br /> This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root.<br /> Note: To successfully exploit this vulnerability on a Cisco NX-OS device, an attacker must have Administrator credentials. The following Cisco devices already allow administrative users to access the underlying operating system through the bash-shell feature, so, for these devices, this vulnerability does not grant any additional privileges:<br /> <br /> Nexus 3000 Series Switches<br /> Nexus 7000 Series Switches that are running Cisco NX-OS Software releases 8.1(1) and later<br /> Nexus 9000 Series Switches in standalone NX-OS mode
Severity CVSS v4.0: Pending analysis
Last modification:
28/10/2025

CVE-2024-36401

Publication date:
01/07/2024
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow Remote Code Execution (RCE) by unauthenticated users through specially crafted input against a default GeoServer installation due to unsafely evaluating property names as XPath expressions.<br /> <br /> The GeoTools library API that GeoServer calls evaluates property/attribute names for feature types in a way that unsafely passes them to the commons-jxpath library which can execute arbitrary code when evaluating XPath expressions. This XPath evaluation is intended to be used only by complex feature types (i.e., Application Schema data stores) but is incorrectly being applied to simple feature types as well which makes this vulnerability apply to **ALL** GeoServer instances. No public PoC is provided but this vulnerability has been confirmed to be exploitable through WFS GetFeature, WFS GetPropertyValue, WMS GetMap, WMS GetFeatureInfo, WMS GetLegendGraphic and WPS Execute requests. This vulnerability can lead to executing arbitrary code.<br /> <br /> Versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2 contain a patch for the issue. A workaround exists by removing the `gt-complex-x.y.jar` file from the GeoServer where `x.y` is the GeoTools version (e.g., `gt-complex-31.1.jar` if running GeoServer 2.25.1). This will remove the vulnerable code from GeoServer but may break some GeoServer functionality or prevent GeoServer from deploying if the gt-complex module is needed.
Severity CVSS v4.0: Pending analysis
Last modification:
24/10/2025

CVE-2024-36420

Publication date:
01/07/2024
Flowise is a drag &amp; drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the `/api/v1/openai-assistants-file` endpoint in `index.ts` is vulnerable to arbitrary file read due to lack of sanitization of the `fileName` body parameter. No known patches for this issue are available.
Severity CVSS v4.0: Pending analysis
Last modification:
03/07/2024

CVE-2024-36421

Publication date:
01/07/2024
Flowise is a drag &amp; drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, A CORS misconfiguration sets the Access-Control-Allow-Origin header to all, allowing arbitrary origins to connect to the website. In the default configuration (unauthenticated), arbitrary origins may be able to make requests to Flowise, stealing information from the user. This CORS misconfiguration may be chained with the path injection to allow an attacker attackers without access to Flowise to read arbitrary files from the Flowise server. As of time of publication, no known patches are available.
Severity CVSS v4.0: Pending analysis
Last modification:
03/07/2024

CVE-2024-36422

Publication date:
01/07/2024
Flowise is a drag &amp; drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting vulnerability occurs in the `api/v1/chatflows/id` endpoint. If the default configuration is used (unauthenticated), an attacker may be able to craft a specially crafted URL that injects Javascript into the user sessions, allowing the attacker to steal information, create false popups, or even redirect the user to other websites without interaction. If the chatflow ID is not found, its value is reflected in the 404 page, which has type text/html. This allows an attacker to attach arbitrary scripts to the page, allowing an attacker to steal sensitive information. This XSS may be chained with the path injection to allow an attacker without direct access to Flowise to read arbitrary files from the Flowise server. As of time of publication, no known patches are available.
Severity CVSS v4.0: Pending analysis
Last modification:
03/07/2024

CVE-2024-6375

Publication date:
01/07/2024
A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading to either degradation of query performance, or to revealing chunk boundaries through timing side channels. This affects MongoDB Server v5.0 versions, prior to 5.0.22, MongoDB Server v6.0 versions, prior to 6.0.11 and MongoDB Server v7.0 versions prior to 7.0.3.
Severity CVSS v4.0: Pending analysis
Last modification:
03/07/2024

CVE-2024-6376

Publication date:
01/07/2024
MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass&amp;#39; connection handling. This issue affects MongoDB Compass versions prior to version 1.42.2
Severity CVSS v4.0: Pending analysis
Last modification:
03/07/2024

CVE-2024-23372

Publication date:
01/07/2024
Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size.
Severity CVSS v4.0: Pending analysis
Last modification:
02/07/2024