Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-22247

Publication date:
02/04/2024
VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability.<br /> <br /> A malicious actor with physical access to the SD-WAN Edge appliance <br /> during activation can potentially exploit this vulnerability to access <br /> the BIOS configuration. In addition, the malicious actor may be able to <br /> exploit the default boot priority configured.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
03/07/2024

CVE-2024-30248

Publication date:
02/04/2024
Piccolo Admin is an admin interface/content management system for Python, built on top of Piccolo. Piccolo&amp;#39;s admin panel allows media files to be uploaded. As a default, SVG is an allowed file type for upload. An attacker can upload an SVG which when loaded can allow arbitrary access to the admin page. This vulnerability was patched in version 1.3.2.
Severity CVSS v4.0: Pending analysis
Last modification:
02/04/2024

CVE-2024-22780

Publication date:
02/04/2024
Cross Site Scripting vulnerability in CA17 TeamsACS v.1.0.1 allows a remote attacker to execute arbitrary code via a crafted script to the errmsg parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
04/12/2024

CVE-2024-30620

Publication date:
02/04/2024
Tenda AX1803 v1.0.0.1 contains a stack overflow via the serviceName parameter in the function fromAdvSetMacMtuWan.
Severity CVSS v4.0: Pending analysis
Last modification:
25/03/2025

CVE-2024-30621

Publication date:
02/04/2024
Tenda AX1803 v1.0.0.1 contains a stack overflow via the serverName parameter in the function fromAdvSetMacMtuWan.
Severity CVSS v4.0: Pending analysis
Last modification:
19/08/2024

CVE-2024-30965

Publication date:
02/04/2024
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/member_scores.php.
Severity CVSS v4.0: Pending analysis
Last modification:
01/04/2025

CVE-2023-50313

Publication date:
02/04/2024
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration. IBM X-Force ID: 274812.
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2024

CVE-2024-29514

Publication date:
02/04/2024
File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file.
Severity CVSS v4.0: Pending analysis
Last modification:
01/05/2025

CVE-2024-2389

Publication date:
02/04/2024
In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.  An unauthenticated user can gain entry to the system via the Flowmon management interface, allowing for the execution of arbitrary system commands.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
07/02/2025

CVE-2024-30946

Publication date:
02/04/2024
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/co_do.php.
Severity CVSS v4.0: Pending analysis
Last modification:
01/04/2025

CVE-2023-6949

Publication date:
02/04/2024
A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 could allow an attacker to enumerate and download videos and pictures saved on the drone internal or external memory without requiring any kind of authentication.
Severity CVSS v4.0: Pending analysis
Last modification:
02/08/2024

CVE-2023-6950

Publication date:
02/04/2024
An Improper Input Validation vulnerability affecting the FTP service running on the DJI Mavic Mini 3 Pro could allow an attacker to craft a malicious packet containing a malformed path provided to the FTP SIZE command that leads to a denial-of-service attack of the FTP service itself.
Severity CVSS v4.0: Pending analysis
Last modification:
30/09/2024