Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-36760

Publication date:
13/06/2024
A stack overflow vulnerability was found in version 1.18.0 of rhai. The flaw position is: (/ SRC/rhai/SRC/eval/STMT. Rs in rhai: : eval: : STMT: : _ $LT $impl $u20 $rhai.. engine.. Engine$GT$::eval_stmt::h3f1d68ce37fc6e96). Due to the stack overflow is a recursive call/SRC/rhai/SRC/eval/STMT. Rs file eval_stmt_block function.
Severity CVSS v4.0: Pending analysis
Last modification:
03/07/2024

CVE-2024-37022

Publication date:
13/06/2024
Fuji Electric Tellus Lite V-Simulator is vulnerable to an out-of-bounds write, which could allow an attacker to manipulate memory, resulting in execution of arbitrary code.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2024

CVE-2024-37029

Publication date:
13/06/2024
Fuji Electric Tellus Lite V-Simulator <br /> is vulnerable to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2024

CVE-2024-38279

Publication date:
13/06/2024
The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.
Severity CVSS v4.0: MEDIUM
Last modification:
21/11/2024

CVE-2024-38280

Publication date:
13/06/2024
An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text.
Severity CVSS v4.0: HIGH
Last modification:
21/11/2024

CVE-2024-38281

Publication date:
13/06/2024
An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.
Severity CVSS v4.0: HIGH
Last modification:
21/11/2024

CVE-2024-32504

Publication date:
13/06/2024
An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, Exynos W930. The mobile processor lacks proper length checking, which can result in an OOB (Out-of-Bounds) Write vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
13/03/2025

CVE-2024-35325

Publication date:
13/06/2024
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity CVSS v4.0: Pending analysis
Last modification:
28/08/2024

CVE-2024-35326

Publication date:
13/06/2024
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity CVSS v4.0: Pending analysis
Last modification:
28/08/2024

CVE-2024-37279

Publication date:
13/06/2024
A flaw was discovered in Kibana, allowing view-only users of alerting to use the run_soon API making the alerting rule run continuously, potentially affecting the system availability if the alerting rule is running complex queries.
Severity CVSS v4.0: Pending analysis
Last modification:
13/03/2025

CVE-2024-37280

Publication date:
13/06/2024
A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting documents in this index would cause a StackOverflow exception to be thrown and ultimately lead to a Denial of Service. Note that passthrough fields is an experimental feature.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2024

CVE-2024-31956

Publication date:
13/06/2024
An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks proper buffer length checking, which can result in an Out-of-Bounds Write.
Severity CVSS v4.0: Pending analysis
Last modification:
14/03/2025