Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-37568

Publication date:
09/06/2024
lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key. (This is similar to CVE-2022-29217 and CVE-2024-33663.)
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2025

CVE-2024-5458

Publication date:
09/06/2024
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2025

CVE-2024-32081

Publication date:
09/06/2024
Missing Authorization vulnerability in Websupporter Filter Custom Fields & Taxonomies Light.This issue affects Filter Custom Fields & Taxonomies Light: from n/a through 1.05.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2024

CVE-2024-34802

Publication date:
09/06/2024
Missing Authorization vulnerability in AdFoxly AdFoxly – Ad Manager, AdSense Ads & Ads.Txt.This issue affects AdFoxly – Ad Manager, AdSense Ads & Ads.Txt: from n/a through 1.8.5.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2024

CVE-2024-35661

Publication date:
09/06/2024
Missing Authorization vulnerability in SoftLab Upload Fields for WPForms.This issue affects Upload Fields for WPForms: from n/a through 1.0.2.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2024

CVE-2024-35662

Publication date:
09/06/2024
Missing Authorization vulnerability in Andreas Sofantzis Simple COD Fees for WooCommerce.This issue affects Simple COD Fees for WooCommerce: from n/a through 2.0.2.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2024

CVE-2024-31275

Publication date:
09/06/2024
Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.4.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2024

CVE-2024-31276

Publication date:
09/06/2024
Missing Authorization vulnerability in WPFactory Products, Order & Customers Export for WooCommerce.This issue affects Products, Order & Customers Export for WooCommerce: from n/a through 2.0.8.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2024

CVE-2024-31283

Publication date:
09/06/2024
Missing Authorization vulnerability in zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pickup for WooCommerce: from n/a through 1.6.2.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2024

CVE-2024-31284

Publication date:
09/06/2024
Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.9.8.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2024

CVE-2024-31304

Publication date:
09/06/2024
Missing Authorization vulnerability in MultiVendorX WC Marketplace.This issue affects WC Marketplace: from n/a through 4.1.3.
Severity CVSS v4.0: Pending analysis
Last modification:
12/06/2024

CVE-2024-32703

Publication date:
09/06/2024
Missing Authorization vulnerability in reputeinfosystems ARForms.This issue affects ARForms: from n/a through 6.4.
Severity CVSS v4.0: Pending analysis
Last modification:
25/09/2024