Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-47581

Publication date:
15/11/2023
Out-of-bounds read vulnerability exists in TELLUS V4.0.17.0 and earlier and TELLUS Lite V4.0.17.0 and earlier. If a user opens a specially crafted file (X1, V8, or V9 file), information may be disclosed and/or arbitrary code may be executed.
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2024

CVE-2023-47582

Publication date:
15/11/2023
Access of uninitialized pointer vulnerability exists in TELLUS V4.0.17.0 and earlier and TELLUS Lite V4.0.17.0 and earlier. If a user opens a specially crafted file (X1, V8, or V9 file), information may be disclosed and/or arbitrary code may be executed.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2023

CVE-2023-47583

Publication date:
15/11/2023
Multiple out-of-bounds read vulnerabilities exist in TELLUS Simulator V4.0.17.0 and earlier. If a user opens a specially crafted file (X1 or V9 file), information may be disclosed and/or arbitrary code may be executed.
Severity CVSS v4.0: Pending analysis
Last modification:
22/11/2023

CVE-2023-47584

Publication date:
15/11/2023
Out-of-bounds write vulnerability exists in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a user opens a specially crafted VPR file, information may be disclosed and/or arbitrary code may be executed.<br />
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2023

CVE-2023-47585

Publication date:
15/11/2023
Out-of-bounds read vulnerability exists in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a user opens a specially crafted VPR file, information may be disclosed and/or arbitrary code may be executed.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2023

CVE-2023-47586

Publication date:
15/11/2023
Multiple heap-based buffer overflow vulnerabilities exist in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a user opens a specially crafted VPR file, information may be disclosed and/or arbitrary code may be executed.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2023

CVE-2023-40923

Publication date:
15/11/2023
MyPrestaModules ordersexport before v5.0 was discovered to contain multiple SQL injection vulnerabilities at send.php via the key and save_setting parameters.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2023

CVE-2023-41597

Publication date:
15/11/2023
EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.
Severity CVSS v4.0: Pending analysis
Last modification:
20/11/2023

CVE-2023-47445

Publication date:
15/11/2023
Pre-School Enrollment version 1.0 is vulnerable to SQL Injection via the username parameter in preschool/admin/ page.
Severity CVSS v4.0: Pending analysis
Last modification:
20/11/2023

CVE-2023-47446

Publication date:
15/11/2023
Pre-School Enrollment version 1.0 is vulnerable to Cross Site Scripting (XSS) on the profile.php page via fullname parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
20/11/2023

CVE-2023-5984

Publication date:
15/11/2023
<br /> A CWE-494 Download of Code Without Integrity Check vulnerability exists that could allow<br /> modified firmware to be uploaded when an authorized admin user begins a firmware update<br /> procedure which could result in full control over the device.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
14/12/2023

CVE-2023-5985

Publication date:
15/11/2023
<br /> <br /> <br /> A CWE-79 Improper Neutralization of Input During Web Page Generation vulnerability<br /> exists that could cause compromise of a user’s browser when an attacker with admin privileges<br /> has modified system values.<br /> <br /> <br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2023