Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-6505

Publication date:
08/01/2024
The Migrate WordPress Website & Backups WordPress plugin before 1.9.3 does not prevent directory listing in sensitive directories containing export files.
Severity CVSS v4.0: Pending analysis
Last modification:
18/06/2025

CVE-2023-6528

Publication date:
08/01/2024
The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.
Severity CVSS v4.0: Pending analysis
Last modification:
03/06/2025

CVE-2023-6529

Publication date:
08/01/2024
The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to Reflected or Stored XSS, as previous versions have such vulnerabilities.
Severity CVSS v4.0: Pending analysis
Last modification:
18/06/2025

CVE-2023-6532

Publication date:
08/01/2024
The WP Blogs' Planetarium WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Severity CVSS v4.0: Pending analysis
Last modification:
18/06/2025

CVE-2023-6555

Publication date:
08/01/2024
The Email Subscription Popup WordPress plugin before 1.2.20 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Severity CVSS v4.0: Pending analysis
Last modification:
18/06/2025

CVE-2023-6627

Publication date:
08/01/2024
The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API routes, which attackers can abuse to store malicious HTML/Javascript on the site.
Severity CVSS v4.0: Pending analysis
Last modification:
18/06/2025

CVE-2023-6750

Publication date:
08/01/2024
The Clone WordPress plugin before 2.4.3 uses buffer files to store in-progress backup informations, which is stored at a publicly accessible, statically defined file path.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2024

CVE-2023-6845

Publication date:
08/01/2024
The CommentTweets WordPress plugin through 0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
Severity CVSS v4.0: Pending analysis
Last modification:
16/05/2025

CVE-2023-6631

Publication date:
08/01/2024
PowerSYSTEM Center versions 2020 Update 16 and prior contain a vulnerability that may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate privileges.<br /> <br /> <br /> <br /> <br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
11/01/2024

CVE-2023-52208

Publication date:
08/01/2024
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Constant Contact Constant Contact Forms.This issue affects Constant Contact Forms: from n/a through 2.4.2.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
11/01/2024

CVE-2023-52222

Publication date:
08/01/2024
Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.2.2.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
11/01/2024

CVE-2023-5235

Publication date:
08/01/2024
The Ovic Responsive WPBakery WordPress plugin before 1.2.9 does not limit which options can be updated via some of its AJAX actions, which may allow attackers with a subscriber+ account to update blog options, such as &amp;#39;users_can_register&amp;#39; and &amp;#39;default_role&amp;#39;. It also unserializes user input in the process, which may lead to Object Injection attacks.
Severity CVSS v4.0: Pending analysis
Last modification:
11/06/2025