Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-39374

Publication date:
27/06/2024
TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed through the use of hard-coded credentials.
Severity CVSS v4.0: Pending analysis
Last modification:
17/09/2024

CVE-2024-39375

Publication date:
27/06/2024
TELSAT marKoni FM Transmitters are vulnerable to an attacker bypassing authentication and gaining administrator privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
17/09/2024

CVE-2024-39376

Publication date:
27/06/2024
TELSAT marKoni FM Transmitters are vulnerable to users gaining unauthorized access to sensitive information or performing actions beyond their designated permissions.
Severity CVSS v4.0: Pending analysis
Last modification:
17/09/2024

CVE-2023-30430

Publication date:
27/06/2024
IBM Security Verify Access 10.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from trace logs. IBM X-Force ID: 252183.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2024

CVE-2024-28820

Publication date:
27/06/2024
Buffer overflow in the extract_openvpn_cr function in openvpn-cr.c in openvpn-auth-ldap (aka the Three Rings Auth-LDAP plugin for OpenVPN) 2.0.4 allows attackers with a valid LDAP username and who can control the challenge/response password field to pass a string with more than 14 colons into this field and cause a buffer overflow.
Severity CVSS v4.0: Pending analysis
Last modification:
04/11/2024

CVE-2024-6374

Publication date:
27/06/2024
A vulnerability was found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as problematic. This issue affects some unknown processing of the file /subject.php of the component Subject Page. The manipulation of the argument Subject Title/Sybillus Details leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269807.
Severity CVSS v4.0: Pending analysis
Last modification:
27/06/2024

CVE-2024-39156

Publication date:
27/06/2024
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=add.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2025

CVE-2024-39157

Publication date:
27/06/2024
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mudi=del&dataType=&dataID=1.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2025

CVE-2024-39158

Publication date:
27/06/2024
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/userSys_deal.php?mudi=infoSet.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2025

CVE-2024-39153

Publication date:
27/06/2024
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/info_deal.php?mudi=del&dataType=news&dataTypeCN.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2025

CVE-2024-39154

Publication date:
27/06/2024
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=del&dataType=word&dataTypeCN.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2025

CVE-2024-39155

Publication date:
27/06/2024
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mudi=add.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2025