Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-49229

Publication date:
28/12/2023
An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in the administration web service allows read-only, unprivileged users to obtain sensitive information about the device configuration.
Severity CVSS v4.0: Pending analysis
Last modification:
04/01/2024

CVE-2023-49230

Publication date:
28/12/2023
An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows attackers to modify the portals' configurations without prior authentication.
Severity CVSS v4.0: Pending analysis
Last modification:
04/01/2024

CVE-2023-51006

Publication date:
28/12/2023
An issue in the openFile method of Chinese Perpetual Calendar v9.0.0 allows attackers to read any file via unspecified vectors.
Severity CVSS v4.0: Pending analysis
Last modification:
05/01/2024

CVE-2023-51010

Publication date:
28/12/2023
An issue in the export component AdSdkH5Activity of com.sdjictec.qdmetro v4.2.2 allows attackers to open a crafted URL without any filtering or checking.
Severity CVSS v4.0: Pending analysis
Last modification:
05/01/2024

CVE-2023-7124

Publication date:
28/12/2023
A vulnerability, which was classified as problematic, was found in code-projects E-Commerce Site 1.0. Affected is an unknown function of the file search.php. The manipulation of the argument keyword with the input leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249096.
Severity CVSS v4.0: Pending analysis
Last modification:
23/10/2025

CVE-2023-34829

Publication date:
28/12/2023
Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext.
Severity CVSS v4.0: Pending analysis
Last modification:
17/04/2025

CVE-2023-7123

Publication date:
28/12/2023
A vulnerability, which was classified as critical, has been found in SourceCodester Medicine Tracking System 1.0. This issue affects some unknown processing of the file /classes/Master.php? f=save_medicine. The manipulation of the argument id/name/description leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249095.
Severity CVSS v4.0: Pending analysis
Last modification:
23/01/2026

CVE-2023-6879

Publication date:
27/12/2023
Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().
Severity CVSS v4.0: Pending analysis
Last modification:
13/02/2025

CVE-2023-46918

Publication date:
27/12/2023
Phlox com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus has an Android manifest file that contains an entry with the android:allowBackup attribute set to true. This could be leveraged by an attacker with physical access to the device.
Severity CVSS v4.0: Pending analysis
Last modification:
05/01/2024

CVE-2023-49000

Publication date:
27/12/2023
An issue in ArtistScope ArtisBrowser v.34.1.5 and before allows an attacker to bypass intended access restrictions via interaction with the com.artis.browser.IntentReceiverActivity component. NOTE: this is disputed by the vendor, who indicates that ArtisBrowser 34 does not support CSS3.
Severity CVSS v4.0: Pending analysis
Last modification:
20/09/2024

CVE-2023-49001

Publication date:
27/12/2023
An issue in Indi Browser (aka kvbrowser) v.12.11.23 allows an attacker to bypass intended access restrictions via interaction with the com.example.gurry.kvbrowswer.webview component.
Severity CVSS v4.0: Pending analysis
Last modification:
09/09/2024

CVE-2023-49002

Publication date:
27/12/2023
An issue in Xenom Technologies (sinous) Phone Dialer-voice Call Dialer v.1.2.5 allows an attacker to bypass intended access restrictions via interaction with com.funprime.calldialer.ui.activities.OutgoingActivity.
Severity CVSS v4.0: Pending analysis
Last modification:
05/01/2024