Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-32753

Publication date:
16/06/2023
OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service.
Severity CVSS v4.0: Pending analysis
Last modification:
30/06/2023

CVE-2023-32752

Publication date:
16/06/2023
L7 Networks InstantScan IS-8000 & InstantQoS IQ-8000’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service.
Severity CVSS v4.0: Pending analysis
Last modification:
03/07/2023

CVE-2023-3291

Publication date:
16/06/2023
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.2.
Severity CVSS v4.0: Pending analysis
Last modification:
15/07/2023

CVE-2023-32027

Publication date:
16/06/2023
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
29/05/2024

CVE-2023-32028

Publication date:
16/06/2023
Microsoft SQL OLE DB Remote Code Execution Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
29/05/2024

CVE-2023-32026

Publication date:
16/06/2023
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
29/05/2024

CVE-2023-29349

Publication date:
16/06/2023
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
29/05/2024

CVE-2023-29356

Publication date:
16/06/2023
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
29/05/2024

CVE-2023-32025

Publication date:
16/06/2023
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
29/05/2024

CVE-2023-2080

Publication date:
15/06/2023
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud allows Blind SQL Injection.
Severity CVSS v4.0: Pending analysis
Last modification:
30/06/2023

CVE-2023-28810

Publication date:
15/06/2023
Some access control/intercom products have unauthorized modification of device network configuration vulnerabilities. Attackers can modify device network configuration by sending specific data packets to the vulnerable interface within the same local network.
Severity CVSS v4.0: Pending analysis
Last modification:
30/06/2023

CVE-2023-23841

Publication date:
15/06/2023
<br /> SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request.  Part of the URL of the request discloses sensitive data. <br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023