Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-4222

Publication date:
28/11/2023
Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS
Severity CVSS v4.0: Pending analysis
Last modification:
30/11/2023

CVE-2023-4223

Publication date:
28/11/2023
Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS
Severity CVSS v4.0: Pending analysis
Last modification:
30/11/2023

CVE-2023-48023

Publication date:
28/11/2023
Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment
Severity CVSS v4.0: Pending analysis
Last modification:
11/10/2024

CVE-2023-4220

Publication date:
28/11/2023
Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS
Severity CVSS v4.0: Pending analysis
Last modification:
04/12/2023

CVE-2023-4221

Publication date:
28/11/2023
Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS
Severity CVSS v4.0: Pending analysis
Last modification:
30/11/2023

CVE-2023-48022

Publication date:
28/11/2023
Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment. (Also, within that environment, customers at version 2.52.0 and later can choose to use token authentication.)
Severity CVSS v4.0: Pending analysis
Last modification:
17/12/2025

CVE-2023-3533

Publication date:
28/11/2023
Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS
Severity CVSS v4.0: Pending analysis
Last modification:
05/12/2023

CVE-2023-3545

Publication date:
28/11/2023
Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS
Severity CVSS v4.0: Pending analysis
Last modification:
04/12/2023

CVE-2023-24023

Publication date:
28/11/2023
Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow certain man-in-the-middle attacks that force a short key length, and might lead to discovery of the encryption key and live injection, aka BLUFFS.
Severity CVSS v4.0: Pending analysis
Last modification:
01/08/2024

CVE-2023-3368

Publication date:
28/11/2023
Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS
Severity CVSS v4.0: Pending analysis
Last modification:
04/12/2023

CVE-2023-49075

Publication date:
28/11/2023
The Admin Classic Bundle provides a Backend UI for Pimcore. `AdminBundle\Security\PimcoreUserTwoFactorCondition` introduced in v11 disable the two factor authentication for all non-admin security firewalls. An authenticated user can access the system without having to provide the two factor credentials. This issue has been patched in version 1.2.2.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
04/12/2023

CVE-2023-6225

Publication date:
28/11/2023
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin&amp;#39;s su_meta shortcode combined with post meta data in all versions up to, and including, 5.13.3 due to insufficient input sanitization and output escaping on user supplied meta values. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity CVSS v4.0: Pending analysis
Last modification:
04/12/2023