Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-0879

Publication date:
25/01/2024
<br /> Authentication bypass in vector-admin allows a user to register to a vector-admin server while “domain restriction” is active, even when not owning an authorized email address.<br /> <br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
31/01/2024

CVE-2024-22432

Publication date:
25/01/2024
<br /> Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup duration in NMDA MySQL Database backups. User has low privilege access to Networker Client system could potentially exploit this vulnerability, leading to the disclosure of configured MySQL Database user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application Database with privileges of the compromised account.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
01/02/2024

CVE-2024-23855

Publication date:
25/01/2024
A vulnerability has been reported in Cups Easy (Purchase &amp; Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/taxcodemodify.php, in multiple parameters. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.
Severity CVSS v4.0: Pending analysis
Last modification:
15/02/2024

CVE-2023-6282

Publication date:
25/01/2024
IceHrm 23.0.0.OS does not sufficiently encode user-controlled input, which creates a Cross-Site Scripting (XSS) vulnerability via /icehrm/app/fileupload_page.php, in multiple parameters. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload and partially hijacking the victim&amp;#39;s browser.
Severity CVSS v4.0: Pending analysis
Last modification:
31/01/2024

CVE-2023-33757

Publication date:
25/01/2024
A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Android App) v1.8.5 and before allows attackers to eavesdrop on communications via a man-in-the-middle attack.
Severity CVSS v4.0: Pending analysis
Last modification:
20/06/2025

CVE-2023-33758

Publication date:
25/01/2024
Splicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the CLIENT_NAME and DEVICE_GUID fields in the login component.
Severity CVSS v4.0: Pending analysis
Last modification:
20/06/2025

CVE-2023-33759

Publication date:
25/01/2024
SpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts, allowing attackers to bypass authentication via a brute force attack.
Severity CVSS v4.0: Pending analysis
Last modification:
30/05/2025

CVE-2023-33760

Publication date:
25/01/2024
SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow attackers to eavesdrop on communications via a man-in-the-middle attack.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2025

CVE-2024-23307

Publication date:
25/01/2024
Integer Overflow or Wraparound vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (md, raid, raid5 modules) allows Forced Integer Overflow.
Severity CVSS v4.0: Pending analysis
Last modification:
22/01/2025

CVE-2024-22099

Publication date:
25/01/2024
NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows Overflow Buffers. This vulnerability is associated with program files /net/bluetooth/rfcomm/core.C.<br /> <br /> This issue affects Linux kernel: v2.6.12-rc2.
Severity CVSS v4.0: Pending analysis
Last modification:
05/06/2025

CVE-2023-50785

Publication date:
25/01/2024
Zoho ManageEngine ADAudit Plus before 7270 allows admin users to view names of arbitrary directories via path traversal.
Severity CVSS v4.0: Pending analysis
Last modification:
28/10/2024

CVE-2024-23985

Publication date:
25/01/2024
EzServer 6.4.017 allows a denial of service (daemon crash) via a long string, such as one for the RNTO command.
Severity CVSS v4.0: Pending analysis
Last modification:
30/05/2025