Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-0654

Publication date:
29/08/2023
Due to a misconfiguration, the WARP Mobile Client (
Severity CVSS v4.0: Pending analysis
Last modification:
01/09/2023

CVE-2023-38283

Publication date:
29/08/2023
In OpenBGPD before 8.1, incorrect handling of BGP update data (length of path attributes) set by a potentially distant remote actor may cause the system to incorrectly reset a session. This is fixed in OpenBSD 7.3 errata 006.
Severity CVSS v4.0: Pending analysis
Last modification:
07/09/2023

CVE-2021-32050

Publication date:
29/08/2023
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed.<br /> <br /> Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default).<br /> <br /> This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0).
Severity CVSS v4.0: Pending analysis
Last modification:
13/02/2025

CVE-2023-0238

Publication date:
29/08/2023
Due to lack of a security policy, the WARP Mobile Client (
Severity CVSS v4.0: Pending analysis
Last modification:
01/09/2023

CVE-2023-40787

Publication date:
29/08/2023
In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection.
Severity CVSS v4.0: Pending analysis
Last modification:
31/08/2023

CVE-2023-23774

Publication date:
29/08/2023
Motorola EBTS/MBTS Site Controller drops to debug prompt on unhandled exception. The Motorola MBTS Site Controller exposes a debug prompt on the device&amp;#39;s serial port in case of an unhandled exception. This allows an attacker with physical access that is able to trigger such an exception to extract secret key material and/or gain arbitrary code execution on the device.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2024

CVE-2023-23773

Publication date:
29/08/2023
Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-23772

Publication date:
29/08/2023
Motorola MBTS Site Controller fails to check firmware update authenticity. The Motorola MBTS Site Controller lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-23771

Publication date:
29/08/2023
Motorola MBTS Base Radio accepts hard-coded backdoor password. The Motorola MBTS Base Radio Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-23770

Publication date:
29/08/2023
Motorola MBTS Site Controller accepts hard-coded backdoor password. The Motorola MBTS Site Controller Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-32457

Publication date:
29/08/2023
<br /> Dell PowerScale OneFS, versions 8.2.2.x-9.5.0.x, contains an improper privilege management vulnerability. A remote attacker with low privileges could potentially exploit this vulnerability, leading to escalation of privileges.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
01/09/2023

CVE-2023-41363

Publication date:
29/08/2023
In Cerebrate 1.14, a vulnerability in UserSettingsController allows authenticated users to change user settings of other users.
Severity CVSS v4.0: Pending analysis
Last modification:
31/08/2023