Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-5039

Publication date:
29/05/2024
The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity CVSS v4.0: Pending analysis
Last modification:
10/04/2025

CVE-2023-42005

Publication date:
29/05/2024
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4.8 could allow a user with access to the Kubernetes pod, to make system calls compromising the security of containers. IBM X-Force ID: 265264.
Severity CVSS v4.0: Pending analysis
Last modification:
18/08/2025

CVE-2023-52881

Publication date:
29/05/2024
In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> tcp: do not accept ACK of bytes we never sent<br /> <br /> This patch is based on a detailed report and ideas from Yepeng Pan<br /> and Christian Rossow.<br /> <br /> ACK seq validation is currently following RFC 5961 5.2 guidelines:<br /> <br /> The ACK value is considered acceptable only if<br /> it is in the range of ((SND.UNA - MAX.SND.WND)
Severity CVSS v4.0: Pending analysis
Last modification:
27/09/2025

CVE-2024-27313

Publication date:
29/05/2024
Zoho ManageEngine PAM360 is vulnerable to Stored XSS vulnerability. This vulnerability is applicable only in the version 6610.
Severity CVSS v4.0: Pending analysis
Last modification:
27/11/2024

CVE-2024-28826

Publication date:
29/05/2024
Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient permissions to configure the check to read and write local files on the Checkmk site server.
Severity CVSS v4.0: Pending analysis
Last modification:
04/12/2024

CVE-2024-3412

Publication date:
29/05/2024
The WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wpstg_processing AJAX action in all versions up to, and including, 3.4.3. This makes it possible for authenticated attackers, with administrator-level access and above, to upload arbitrary files on the affected site&amp;#39;s server which may make remote code execution possible.
Severity CVSS v4.0: Pending analysis
Last modification:
29/05/2024

CVE-2024-5086

Publication date:
29/05/2024
The Essential Addons for Elementor PRO – Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin&amp;#39;s Team Member Carousel widget in all Pro versions up to, and including, 5.8.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity CVSS v4.0: Pending analysis
Last modification:
01/03/2025

CVE-2024-36015

Publication date:
29/05/2024
In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ppdev: Add an error check in register_device<br /> <br /> In register_device, the return value of ida_simple_get is unchecked,<br /> in witch ida_simple_get will use an invalid index value.<br /> <br /> To address this issue, index should be checked after ida_simple_get. When<br /> the index value is abnormal, a warning message should be printed, the port<br /> should be dropped, and the value should be recorded.
Severity CVSS v4.0: Pending analysis
Last modification:
04/11/2025

CVE-2024-36014

Publication date:
29/05/2024
In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> drm/arm/malidp: fix a possible null pointer dereference<br /> <br /> In malidp_mw_connector_reset, new memory is allocated with kzalloc, but<br /> no check is performed. In order to prevent null pointer dereferencing,<br /> ensure that mw_state is checked before calling<br /> __drm_atomic_helper_connector_reset.
Severity CVSS v4.0: Pending analysis
Last modification:
04/11/2025

CVE-2024-3050

Publication date:
29/05/2024
The Site Reviews WordPress plugin before 7.0.0 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass IP-based blocking
Severity CVSS v4.0: Pending analysis
Last modification:
21/05/2025

CVE-2024-3921

Publication date:
29/05/2024
The Gianism WordPress plugin through 5.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Severity CVSS v4.0: Pending analysis
Last modification:
21/05/2025

CVE-2024-3937

Publication date:
29/05/2024
The Playlist for Youtube WordPress plugin through 1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Severity CVSS v4.0: Pending analysis
Last modification:
21/05/2025