Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-50701

Publication date:
30/12/2024
TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a folder is in a user's allowed folders list that has been defined by an admin.
Severity CVSS v4.0: Pending analysis
Last modification:
29/09/2025

CVE-2024-50702

Publication date:
30/12/2024
TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager.
Severity CVSS v4.0: Pending analysis
Last modification:
29/09/2025

CVE-2024-50703

Publication date:
30/12/2024
TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id.
Severity CVSS v4.0: Pending analysis
Last modification:
29/09/2025

CVE-2024-54181

Publication date:
30/12/2024
IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the system.
Severity CVSS v4.0: Pending analysis
Last modification:
28/03/2025

CVE-2024-10044

Publication date:
30/12/2024
A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in lm-sys/fastchat, as of commit e208d5677c6837d590b81cb03847c0b9de100765. This vulnerability allows attackers to exploit the victim controller API server's credentials to perform unauthorized web actions or access unauthorized web resources by combining it with the POST /register_worker endpoint.
Severity CVSS v4.0: Pending analysis
Last modification:
29/07/2025

CVE-2024-12993

Publication date:
30/12/2024
Infinix devices contain a pre-loaded "com.rlk.weathers" application, that exposes an unsecured content provider. An attacker can communicate with the provider and reveal the user’s location without any privileges. <br /> After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices.
Severity CVSS v4.0: MEDIUM
Last modification:
15/04/2026

CVE-2024-47924

Publication date:
30/12/2024
Boa web server – CWE-79: Improper Neutralization of Input During Web Page Generation (&amp;#39;Cross-site Scripting&amp;#39;)
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2024-47925

Publication date:
30/12/2024
Tecnick TCExam – Multiple CWE-79: Improper Neutralization of Input During Web Page Generation (&amp;#39;Cross-site Scripting&amp;#39;)
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2024-47926

Publication date:
30/12/2024
Tecnick TCExam – CWE-89: Improper Neutralization of Special Elements used in an SQL Command (&amp;#39;SQL Injection&amp;#39;)
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2024-47917

Publication date:
30/12/2024
CWE-79: Improper Neutralization of Input During Web Page Generation (&amp;#39;Cross-site Scripting&amp;#39;)
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2024-47918

Publication date:
30/12/2024
Tiki Wiki CMS – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2024-47919

Publication date:
30/12/2024
Tiki Wiki CMS – CWE-78: Improper Neutralization of Special Elements used in an OS Command (&amp;#39;OS Command Injection&amp;#39;)
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026