Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-4581

Publication date:
04/06/2024
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Add Layer widget in all versions up to, and including, 6.7.11 due to insufficient input sanitization and output escaping on the user supplied 'class', 'id', and 'title' attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: Successful exploitation of this vulnerability requires an Administrator to give Slider Creation privileges to Author-level users.
Severity CVSS v4.0: Pending analysis
Last modification:
27/01/2025

CVE-2024-5000

Publication date:
04/06/2024
An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS products which can cause a DoS due to incorrect calculation of buffer size.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
04/06/2024

CVE-2024-5420

Publication date:
04/06/2024
Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 web-interface allows stored Cross-Site Scripting (XSS)..This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.
Severity CVSS v4.0: HIGH
Last modification:
08/10/2025

CVE-2024-5421

Publication date:
04/06/2024
Missing input validation and OS command integration of the input in the utnserver Pro, utnserver ProMAX, INU-100 web-interface allows authenticated command injection.This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.
Severity CVSS v4.0: Pending analysis
Last modification:
10/06/2024

CVE-2024-5422

Publication date:
04/06/2024
An uncontrolled resource consumption of file descriptors in SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 allows DoS via HTTP.This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.
Severity CVSS v4.0: Pending analysis
Last modification:
10/06/2024

CVE-2023-41134

Publication date:
04/06/2024
Authentication Bypass by Spoofing vulnerability in pluginkollektiv Antispam Bee allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Antispam Bee: from n/a through 2.11.3.
Severity CVSS v4.0: Pending analysis
Last modification:
04/06/2024

CVE-2023-44235

Publication date:
04/06/2024
Improper Restriction of Excessive Authentication Attempts vulnerability in Devnath verma WP Captcha allows Functionality Bypass.This issue affects WP Captcha: from n/a through 2.0.0.
Severity CVSS v4.0: Pending analysis
Last modification:
04/06/2024

CVE-2024-36104

Publication date:
04/06/2024
Improper Limitation of a Pathname to a Restricted Directory (&amp;#39;Path Traversal&amp;#39;) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14.<br /> <br /> Users are recommended to upgrade to version 18.12.14, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
01/07/2025

CVE-2024-4253

Publication date:
04/06/2024
A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the &amp;#39;test-functional.yml&amp;#39; workflow. The vulnerability arises due to improper neutralization of special elements used in a command, allowing for unauthorized modification of the base repository or secrets exfiltration. The issue affects versions up to and including &amp;#39;@gradio/video@0.6.12&amp;#39;. The flaw is present in the workflow&amp;#39;s handling of GitHub context information, where it echoes the full name of the head repository, the head branch, and the workflow reference without adequate sanitization. This could potentially lead to the exfiltration of sensitive secrets such as &amp;#39;GITHUB_TOKEN&amp;#39;, &amp;#39;COMMENT_TOKEN&amp;#39;, and &amp;#39;CHROMATIC_PROJECT_TOKEN&amp;#39;.
Severity CVSS v4.0: Pending analysis
Last modification:
15/10/2025

CVE-2023-39161

Publication date:
04/06/2024
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Discussion Board Discussion Board allows Content Spoofing, Cross-Site Scripting (XSS).This issue affects Discussion Board: from n/a through 2.4.8.
Severity CVSS v4.0: Pending analysis
Last modification:
04/06/2024

CVE-2023-40332

Publication date:
04/06/2024
Improper Control of Interaction Frequency vulnerability in Lester ‘GaMerZ’ Chan WP-PostRatings allows Functionality Misuse.This issue affects WP-PostRatings: from n/a through 1.91.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2023-40557

Publication date:
04/06/2024
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in PickPlugins Tabs &amp; Accordion allows Code Injection.This issue affects Tabs &amp; Accordion: from n/a through 1.3.10.
Severity CVSS v4.0: Pending analysis
Last modification:
04/06/2024