Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-24681

Publication date:
23/02/2024
An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is a single hardcoded key (used to encrypt provisioning documents) across customers' installations.
Severity CVSS v4.0: Pending analysis
Last modification:
04/11/2025

CVE-2024-25730

Publication date:
23/02/2024
Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a "Hitron" substring, resulting in insufficient entropy (only about one million possibilities).
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2025

CVE-2024-27132

Publication date:
23/02/2024
Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe.<br /> <br /> This issue leads to a client-side RCE when running an untrusted recipe in Jupyter Notebook.<br /> <br /> The vulnerability stems from lack of sanitization over template variables.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
22/01/2025

CVE-2024-27133

Publication date:
23/02/2024
Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset. This issue leads to a client-side RCE when running the recipe in Jupyter Notebook. The vulnerability stems from lack of sanitization over dataset table fields.
Severity CVSS v4.0: Pending analysis
Last modification:
22/01/2025

CVE-2024-21423

Publication date:
23/02/2024
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
29/11/2024

CVE-2024-24309

Publication date:
23/02/2024
In the module "Survey TMA" (ecomiz_survey_tma) up to version 2.0.0 from Ecomiz for PrestaShop, a guest can download personal information without restriction.
Severity CVSS v4.0: Pending analysis
Last modification:
08/05/2025

CVE-2024-24310

Publication date:
23/02/2024
In the module "Generate barcode on invoice / delivery slip" (ecgeneratebarcode) from Ether Creation
Severity CVSS v4.0: Pending analysis
Last modification:
08/05/2025

CVE-2021-3885

Publication date:
23/02/2024
Rejected reason: This is unused.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2025

CVE-2021-41851

Publication date:
23/02/2024
Rejected reason: This is unused.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2025

CVE-2021-41852

Publication date:
23/02/2024
Rejected reason: This is unused.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2025

CVE-2021-41853

Publication date:
23/02/2024
Rejected reason: This is unused.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2025

CVE-2021-41854

Publication date:
23/02/2024
Rejected reason: This is unused.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2025