Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-32091

Publication date:
15/04/2024
Cross-Site Request Forgery (CSRF) vulnerability in Tonjoo Sangar Slider.This issue affects Sangar Slider: from n/a through 1.3.2.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2024

CVE-2024-32092

Publication date:
15/04/2024
Cross-Site Request Forgery (CSRF) vulnerability in Michael Bester Kimili Flash Embed.This issue affects Kimili Flash Embed: from n/a through 2.5.3.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2024

CVE-2024-32093

Publication date:
15/04/2024
Cross-Site Request Forgery (CSRF) vulnerability in Nose Graze Novelist.This issue affects Novelist: from n/a through 1.2.2.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2024

CVE-2024-32090

Publication date:
15/04/2024
Cross-Site Request Forgery (CSRF) vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.0.27.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
21/01/2026

CVE-2024-31941

Publication date:
15/04/2024
Cross-Site Request Forgery (CSRF) vulnerability in CodePeople CP Media Player.This issue affects CP Media Player: from n/a through 1.1.3.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2024

CVE-2024-31942

Publication date:
15/04/2024
Cross-Site Request Forgery (CSRF) vulnerability in Typps Calendarista Basic Edition.This issue affects Calendarista Basic Edition: from n/a through 3.0.2.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2024

CVE-2024-32084

Publication date:
15/04/2024
Cross-Site Request Forgery (CSRF) vulnerability in Gold Plugins Before And After.This issue affects Before And After: from n/a through 3.9.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2024

CVE-2024-32085

Publication date:
15/04/2024
Cross-Site Request Forgery (CSRF) vulnerability in AitThemes Citadela Listing.This issue affects Citadela Listing: from n/a before 5.20.0.
Severity CVSS v4.0: Pending analysis
Last modification:
29/09/2025

CVE-2024-32088

Publication date:
15/04/2024
Cross-Site Request Forgery (CSRF) vulnerability in SeedProd Coming Soon Page, Under Construction &amp; Maintenance Mode by SeedProd.This issue affects Coming Soon Page, Under Construction &amp; Maintenance Mode by SeedProd: from n/a through 6.15.20.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2024

CVE-2024-22435

Publication date:
15/04/2024
<br /> A potential security vulnerability has been identified in Web ViewPoint Enterprise software. This vulnerability could be exploited to allow unauthorized users to access some resources on a NonStop system.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2024

CVE-2024-3505

Publication date:
15/04/2024
JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration.<br /> This does not affect JFrog cloud deployments.
Severity CVSS v4.0: Pending analysis
Last modification:
01/04/2025

CVE-2024-3701

Publication date:
15/04/2024
The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform malicious exploitations and affect system services.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2025