Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-33541

Publication date:
04/06/2024
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BetterAddons Better Elementor Addons allows PHP Local File Inclusion.This issue affects Better Elementor Addons: from n/a through 1.4.1.
Severity CVSS v4.0: Pending analysis
Last modification:
06/03/2025

CVE-2024-33557

Publication date:
04/06/2024
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore Core allows PHP Local File Inclusion.This issue affects XStore Core: from n/a through 5.3.8.
Severity CVSS v4.0: Pending analysis
Last modification:
26/02/2025

CVE-2023-51543

Publication date:
04/06/2024
Authentication Bypass by Spoofing vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects RegistrationMagic: from n/a through 5.2.5.0.
Severity CVSS v4.0: Pending analysis
Last modification:
04/02/2025

CVE-2023-51544

Publication date:
04/06/2024
Improper Control of Interaction Frequency vulnerability in Metagauss RegistrationMagic allows Functionality Misuse.This issue affects RegistrationMagic: from n/a through 5.2.5.0.
Severity CVSS v4.0: Pending analysis
Last modification:
04/02/2025

CVE-2023-51667

Publication date:
04/06/2024
Authentication Bypass by Spoofing vulnerability in FeedbackWP Rate my Post – WP Rating System allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Rate my Post – WP Rating System: from n/a through 3.4.2.
Severity CVSS v4.0: Pending analysis
Last modification:
29/05/2025

CVE-2023-52147

Publication date:
04/06/2024
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in All In One WP Security & Firewall Team All In One WP Security & Firewall allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects All In One WP Security & Firewall: from n/a through 5.2.4.
Severity CVSS v4.0: Pending analysis
Last modification:
04/06/2024

CVE-2023-52176

Publication date:
04/06/2024
Authentication Bypass by Spoofing vulnerability in miniorange Malware Scanner allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Malware Scanner: from n/a through 4.7.1.
Severity CVSS v4.0: Pending analysis
Last modification:
04/06/2024

CVE-2023-51511

Publication date:
04/06/2024
Improper Authentication vulnerability in Pluggabl LLC Booster Elite for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booster Elite for WooCommerce: from n/a before 7.1.3.
Severity CVSS v4.0: Pending analysis
Last modification:
10/03/2025

CVE-2023-51542

Publication date:
04/06/2024
Authentication Bypass by Spoofing vulnerability in WPMU DEV Branda allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Branda: from n/a through 3.4.14.
Severity CVSS v4.0: Pending analysis
Last modification:
04/06/2024

CVE-2024-37063

Publication date:
04/06/2024
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser.
Severity CVSS v4.0: Pending analysis
Last modification:
04/06/2024

CVE-2024-37064

Publication date:
04/06/2024
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded.
Severity CVSS v4.0: Pending analysis
Last modification:
04/06/2024

CVE-2024-37065

Publication date:
04/06/2024
Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously crafted model to run arbitrary code on an end user's system when loaded.
Severity CVSS v4.0: Pending analysis
Last modification:
04/06/2024