Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-40923

Publication date:
15/11/2023
MyPrestaModules ordersexport before v5.0 was discovered to contain multiple SQL injection vulnerabilities at send.php via the key and save_setting parameters.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2023

CVE-2023-41597

Publication date:
15/11/2023
EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.
Severity CVSS v4.0: Pending analysis
Last modification:
20/11/2023

CVE-2023-47445

Publication date:
15/11/2023
Pre-School Enrollment version 1.0 is vulnerable to SQL Injection via the username parameter in preschool/admin/ page.
Severity CVSS v4.0: Pending analysis
Last modification:
20/11/2023

CVE-2023-47446

Publication date:
15/11/2023
Pre-School Enrollment version 1.0 is vulnerable to Cross Site Scripting (XSS) on the profile.php page via fullname parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
20/11/2023

CVE-2023-5984

Publication date:
15/11/2023
<br /> A CWE-494 Download of Code Without Integrity Check vulnerability exists that could allow<br /> modified firmware to be uploaded when an authorized admin user begins a firmware update<br /> procedure which could result in full control over the device.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
14/12/2023

CVE-2023-5985

Publication date:
15/11/2023
<br /> <br /> <br /> A CWE-79 Improper Neutralization of Input During Web Page Generation vulnerability<br /> exists that could cause compromise of a user’s browser when an attacker with admin privileges<br /> has modified system values.<br /> <br /> <br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2023

CVE-2023-5986

Publication date:
15/11/2023
<br /> A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input<br /> attackers can cause the software’s web application to redirect to the chosen domain after a<br /> successful login is performed. <br /> <br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
30/11/2023

CVE-2023-5987

Publication date:
15/11/2023
<br /> A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)<br /> vulnerability that could cause a vulnerability leading to a cross site scripting condition where<br /> attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing<br /> the injected payload.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
30/11/2023

CVE-2023-6032

Publication date:
15/11/2023
<br /> A CWE-22: Improper Limitation of a Pathname to a Restricted Directory (&amp;#39;Path Traversal&amp;#39;)<br /> vulnerability exists that could cause a file system enumeration and file download when an<br /> attacker navigates to the Network Management Card via HTTPS.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
30/11/2023

CVE-2023-47678

Publication date:
15/11/2023
An improper access control vulnerability exists in RT-AC87U all versions. An attacker may read or write files that are not intended to be accessed by connecting to a target device via tftp.
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2024

CVE-2023-43979

Publication date:
15/11/2023
ETS Soft ybc_blog before v4.4.0 was discovered to contain a SQL injection vulnerability via the component Ybc_blogBlogModuleFrontController::getPosts().
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2023

CVE-2023-47308

Publication date:
15/11/2023
In the module "Newsletter Popup PRO with Voucher/Coupon code" (newsletterpop) before version 2.6.1 from Active Design for PrestaShop, a guest can perform SQL injection in affected versions. The method `NewsletterpopsendVerificationModuleFrontController::checkEmailSubscription()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2023