Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-25128

Publication date:
29/02/2024
Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, it allows an attacker to forge an HTTP request, that could deceive the backend into using any requested OpenID service. This vulnerability could grant an attacker unauthorised privilege access if a custom OpenID service is deployed by the attacker and accessible by the backend. This vulnerability is only exploitable when the application is using the OpenID 2.0 authorization protocol. Upgrade to Flask-AppBuilder 4.3.11 to fix the vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
14/10/2025

CVE-2024-24701

Publication date:
29/02/2024
Cross-Site Request Forgery (CSRF) vulnerability in Native Grid LLC A no-code page builder for beautiful performance-based content.This issue affects A no-code page builder for beautiful performance-based content: from n/a through 2.1.20.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2025

CVE-2024-24708

Publication date:
29/02/2024
Cross-Site Request Forgery (CSRF) vulnerability in W3speedster W3SPEEDSTER.This issue affects W3SPEEDSTER: from n/a through 7.19.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
07/05/2025

CVE-2024-23946

Publication date:
29/02/2024
Possible path traversal in Apache OFBiz allowing file inclusion.<br /> Users are recommended to upgrade to version 18.12.12, that fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
13/08/2024

CVE-2024-24146

Publication date:
29/02/2024
A memory leak issue discovered in parseSWF_DEFINEBUTTON in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.
Severity CVSS v4.0: Pending analysis
Last modification:
27/03/2025

CVE-2024-24147

Publication date:
29/02/2024
A memory leak issue discovered in parseSWF_FILLSTYLEARRAY in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.
Severity CVSS v4.0: Pending analysis
Last modification:
29/08/2024

CVE-2024-24149

Publication date:
29/02/2024
A memory leak issue discovered in parseSWF_GLYPHENTRY in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.
Severity CVSS v4.0: Pending analysis
Last modification:
13/08/2024

CVE-2024-24150

Publication date:
29/02/2024
A memory leak issue discovered in parseSWF_TEXTRECORD in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.
Severity CVSS v4.0: Pending analysis
Last modification:
27/03/2025

CVE-2024-24155

Publication date:
29/02/2024
Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot correctly delete when we got an no audio track found error. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mp4 file.
Severity CVSS v4.0: Pending analysis
Last modification:
16/01/2025

CVE-2024-23807

Publication date:
29/02/2024
The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs.<br /> <br /> Users are recommended to upgrade to version 3.2.5 which fixes the issue, or mitigate the issue by disabling DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable.<br /> <br /> This issue has been disclosed before as CVE-2018-1311, but unfortunately that advisory incorrectly stated the issue would be fixed in version 3.2.3 or 3.2.4.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
16/01/2025

CVE-2024-23519

Publication date:
29/02/2024
Cross-Site Request Forgery (CSRF) vulnerability in M&amp;S Consulting Email Before Download.This issue affects Email Before Download: from n/a through 6.9.7.
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2025

CVE-2024-23302

Publication date:
29/02/2024
Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.
Severity CVSS v4.0: Pending analysis
Last modification:
16/01/2025