Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-23946

Publication date:
29/02/2024
Possible path traversal in Apache OFBiz allowing file inclusion.<br /> Users are recommended to upgrade to version 18.12.12, that fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
13/08/2024

CVE-2024-24146

Publication date:
29/02/2024
A memory leak issue discovered in parseSWF_DEFINEBUTTON in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.
Severity CVSS v4.0: Pending analysis
Last modification:
27/03/2025

CVE-2024-24147

Publication date:
29/02/2024
A memory leak issue discovered in parseSWF_FILLSTYLEARRAY in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.
Severity CVSS v4.0: Pending analysis
Last modification:
29/08/2024

CVE-2024-24149

Publication date:
29/02/2024
A memory leak issue discovered in parseSWF_GLYPHENTRY in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.
Severity CVSS v4.0: Pending analysis
Last modification:
13/08/2024

CVE-2024-24150

Publication date:
29/02/2024
A memory leak issue discovered in parseSWF_TEXTRECORD in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.
Severity CVSS v4.0: Pending analysis
Last modification:
27/03/2025

CVE-2024-24155

Publication date:
29/02/2024
Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot correctly delete when we got an no audio track found error. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mp4 file.
Severity CVSS v4.0: Pending analysis
Last modification:
16/01/2025

CVE-2024-23807

Publication date:
29/02/2024
The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs.<br /> <br /> Users are recommended to upgrade to version 3.2.5 which fixes the issue, or mitigate the issue by disabling DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable.<br /> <br /> This issue has been disclosed before as CVE-2018-1311, but unfortunately that advisory incorrectly stated the issue would be fixed in version 3.2.3 or 3.2.4.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
16/01/2025

CVE-2024-23519

Publication date:
29/02/2024
Cross-Site Request Forgery (CSRF) vulnerability in M&amp;S Consulting Email Before Download.This issue affects Email Before Download: from n/a through 6.9.7.
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2025

CVE-2024-23302

Publication date:
29/02/2024
Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.
Severity CVSS v4.0: Pending analysis
Last modification:
16/01/2025

CVE-2024-23328

Publication date:
29/02/2024
Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The location of the vulnerability code is `core/core-backend/src/main/java/io/dataease/datasource/type/Mysql.java.` The blacklist of mysql jdbc attacks can be bypassed and attackers can further exploit it for deserialized execution or reading arbitrary files. This vulnerability is patched in 1.18.15 and 2.3.0.
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2025

CVE-2024-22936

Publication date:
29/02/2024
Cross-site scripting (XSS) vulnerability in Parents &amp; Student Portal in Genesis School Management Systems in Genesis AIMS Student Information Systems v.3053 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
16/01/2025

CVE-2024-22939

Publication date:
29/02/2024
Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the system/article/category_edit component.
Severity CVSS v4.0: Pending analysis
Last modification:
16/01/2025