Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-7518

Publication date:
06/08/2024
Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
29/10/2024

CVE-2024-43114

Publication date:
06/08/2024
In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions
Severity CVSS v4.0: Pending analysis
Last modification:
11/09/2024

CVE-2024-33991

Publication date:
06/08/2024
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/eventwinner/index.php'.
Severity CVSS v4.0: Pending analysis
Last modification:
15/08/2024

CVE-2024-33992

Publication date:
06/08/2024
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/student/index.php'.
Severity CVSS v4.0: Pending analysis
Last modification:
15/08/2024

CVE-2024-33993

Publication date:
06/08/2024
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in /candidate/index.php'.
Severity CVSS v4.0: Pending analysis
Last modification:
15/08/2024

CVE-2024-33994

Publication date:
06/08/2024
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in '/event/index.php'.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2024

CVE-2024-33986

Publication date:
06/08/2024
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter in '/department/index.php'.
Severity CVSS v4.0: Pending analysis
Last modification:
15/08/2024

CVE-2024-33987

Publication date:
06/08/2024
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance', 'attenddate', 'YearLevel', 'eventdate', 'events', 'Users' and 'YearLevel' parameters in '/report/index.php'.
Severity CVSS v4.0: Pending analysis
Last modification:
15/08/2024

CVE-2024-33988

Publication date:
06/08/2024
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance', 'attenddate' and 'YearLevel' parameters in '/report/attendance_print.php'.
Severity CVSS v4.0: Pending analysis
Last modification:
15/08/2024

CVE-2024-33989

Publication date:
06/08/2024
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser session via the 'eventdate' and 'events' parameters in 'port/event_print.php'.
Severity CVSS v4.0: Pending analysis
Last modification:
15/08/2024

CVE-2024-33990

Publication date:
06/08/2024
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser session via the 'id' and 'view' parameters in '/user/index.php'.
Severity CVSS v4.0: Pending analysis
Last modification:
15/08/2024

CVE-2024-33982

Publication date:
06/08/2024
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'StudentID' parameter in '/AttendanceMonitoring/student/controller.php'.
Severity CVSS v4.0: Pending analysis
Last modification:
15/08/2024