Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-37621

Publication date:
17/06/2024
StrongShop v1.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the component /shippingOptionConfig/index.blade.php.
Severity CVSS v4.0: Pending analysis
Last modification:
20/06/2025

CVE-2024-37622

Publication date:
17/06/2024
Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the num parameter at /flow/flow.php.
Severity CVSS v4.0: Pending analysis
Last modification:
30/04/2025

CVE-2024-37623

Publication date:
17/06/2024
Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /kaoqin/tpl_kaoqin_locationchange.html component.
Severity CVSS v4.0: Pending analysis
Last modification:
30/04/2025

CVE-2024-37624

Publication date:
17/06/2024
Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /chajian/inputChajian.php. component.
Severity CVSS v4.0: Pending analysis
Last modification:
17/03/2025

CVE-2024-37625

Publication date:
17/06/2024
zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /index.php.
Severity CVSS v4.0: Pending analysis
Last modification:
20/08/2024

CVE-2024-37848

Publication date:
17/06/2024
SQL Injection vulnerability in Online-Bookstore-Project-In-PHP v1.0 allows a local attacker to execute arbitrary code via the admin_delete.php component.
Severity CVSS v4.0: Pending analysis
Last modification:
05/11/2025

CVE-2024-36580

Publication date:
17/06/2024
A Prototype Pollution issue in cdr0 sg 1.0.10 allows an attacker to execute arbitrary code.
Severity CVSS v4.0: Pending analysis
Last modification:
22/08/2024

CVE-2024-36583

Publication date:
17/06/2024
A Prototype Pollution issue in byondreal accessor
Severity CVSS v4.0: Pending analysis
Last modification:
03/07/2024

CVE-2024-37158

Publication date:
17/06/2024
Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Preliminary checks on actions computed by the clawback vesting accounts are performed in the ante handler. Evmos core, implements two different ante handlers: one for Cosmos transactions and one for Ethereum transactions. Checks performed on the two implementation are different. The vulnerability discovered allowed a clawback account to bypass Cosmos ante handler checks by sending an Ethereum transaction targeting a precompile used to interact with a Cosmos SDK module. This vulnerability is fixed in 18.0.0.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
07/03/2025

CVE-2024-37159

Publication date:
17/06/2024
Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. This vulnerability allowed a user to create a validator using vested tokens to deposit the self-bond. This vulnerability is fixed in 18.0.0.
Severity CVSS v4.0: Pending analysis
Last modification:
07/03/2025

CVE-2024-37619

Publication date:
17/06/2024
StrongShop v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the spec_group_id parameter at /spec/index.blade.php.
Severity CVSS v4.0: Pending analysis
Last modification:
01/08/2024

CVE-2024-6055

Publication date:
17/06/2024
Improper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32.0 and earlier on Windows allows an attacker that obtains the exported settings to recover powershell credentials configured on the data source via stealing the configuration file.
Severity CVSS v4.0: Pending analysis
Last modification:
28/03/2025