Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-48022

Publication date:
28/11/2023
Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment. (Also, within that environment, customers at version 2.52.0 and later can choose to use token authentication.)
Severity CVSS v4.0: Pending analysis
Last modification:
17/12/2025

CVE-2023-3533

Publication date:
28/11/2023
Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS
Severity CVSS v4.0: Pending analysis
Last modification:
05/12/2023

CVE-2023-3545

Publication date:
28/11/2023
Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS
Severity CVSS v4.0: Pending analysis
Last modification:
04/12/2023

CVE-2023-24023

Publication date:
28/11/2023
Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow certain man-in-the-middle attacks that force a short key length, and might lead to discovery of the encryption key and live injection, aka BLUFFS.
Severity CVSS v4.0: Pending analysis
Last modification:
01/08/2024

CVE-2023-3368

Publication date:
28/11/2023
Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS
Severity CVSS v4.0: Pending analysis
Last modification:
04/12/2023

CVE-2023-49075

Publication date:
28/11/2023
The Admin Classic Bundle provides a Backend UI for Pimcore. `AdminBundle\Security\PimcoreUserTwoFactorCondition` introduced in v11 disable the two factor authentication for all non-admin security firewalls. An authenticated user can access the system without having to provide the two factor credentials. This issue has been patched in version 1.2.2.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
04/12/2023

CVE-2023-6225

Publication date:
28/11/2023
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin&amp;#39;s su_meta shortcode combined with post meta data in all versions up to, and including, 5.13.3 due to insufficient input sanitization and output escaping on user supplied meta values. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity CVSS v4.0: Pending analysis
Last modification:
04/12/2023

CVE-2023-6226

Publication date:
28/11/2023
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.13.3 via the su_meta shortcode due to missing validation on the user controlled keys &amp;#39;key&amp;#39; and &amp;#39;post_id&amp;#39;. This makes it possible for authenticated attackers, with contributor-level access and above, to retrieve arbitrary post meta values which may contain sensitive information when combined with another plugin.
Severity CVSS v4.0: Pending analysis
Last modification:
04/12/2023

CVE-2023-32063

Publication date:
28/11/2023
OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call event, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.4 and 5.1.1.
Severity CVSS v4.0: Pending analysis
Last modification:
01/12/2023

CVE-2023-32064

Publication date:
28/11/2023
OroCommerce package with customer portal and non authenticated visitor website base features. Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.11 and 5.1.1.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
01/12/2023

CVE-2023-32065

Publication date:
28/11/2023
OroCommerce is an open-source Business to Business Commerce application built with flexibility in mind. Detailed Order totals information may be received by Order ID. This issue is patched in version 5.0.11 and 5.1.1.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
01/12/2023

CVE-2023-48713

Publication date:
28/11/2023
Knative Serving builds on Kubernetes to support deploying and serving of applications and functions as serverless containers. An attacker who controls a pod to a degree where they can control the responses from the /metrics endpoint can cause Denial-of-Service of the autoscaler from an unbound memory allocation bug. This is a DoS vulnerability, where a non-privileged Knative user can cause a DoS for the cluster. This issue has been patched in version 0.39.0.
Severity CVSS v4.0: Pending analysis
Last modification:
01/12/2023