Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-47229

Publication date:
08/11/2023
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Vyas Dipen Top 25 Social Icons plugin
Severity CVSS v4.0: Pending analysis
Last modification:
15/11/2023

CVE-2023-47231

Publication date:
08/11/2023
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Bainternet ShortCodes UI plugin
Severity CVSS v4.0: Pending analysis
Last modification:
15/11/2023

CVE-2023-47181

Publication date:
08/11/2023
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Gibson IdeaPush plugin
Severity CVSS v4.0: Pending analysis
Last modification:
15/11/2023

CVE-2023-47190

Publication date:
08/11/2023
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Apollo13Themes Apollo13 Framework Extensions plugin
Severity CVSS v4.0: Pending analysis
Last modification:
14/11/2023

CVE-2023-47223

Publication date:
08/11/2023
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Map Plugins Basic Interactive World Map plugin
Severity CVSS v4.0: Pending analysis
Last modification:
19/02/2025

CVE-2023-3282

Publication date:
08/11/2023
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system enables a local attacker to execute programs with elevated privileges if the attacker has shell access to the engine.
Severity CVSS v4.0: Pending analysis
Last modification:
16/11/2023

CVE-2023-5913

Publication date:
08/11/2023
Incorrect Privilege Assignment vulnerability in opentext Fortify ScanCentral DAST. The vulnerability could be exploited to gain elevated privileges.This issue affects Fortify ScanCentral DAST versions 21.1, 21.2, 21.2.1, 22.1, 22.1.1, 22.2, 23.1.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2024

CVE-2023-46642

Publication date:
08/11/2023
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in sahumedia SAHU TikTok Pixel for E-Commerce plugin
Severity CVSS v4.0: Pending analysis
Last modification:
15/11/2023

CVE-2023-46643

Publication date:
08/11/2023
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GARY JEZORSKI CloudNet360 plugin
Severity CVSS v4.0: Pending analysis
Last modification:
29/10/2024

CVE-2023-47379

Publication date:
08/11/2023
Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality.
Severity CVSS v4.0: Pending analysis
Last modification:
15/11/2023

CVE-2023-5760

Publication date:
08/11/2023
A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be further exploited, allowing an attacker to gain full local privilege escalation on the system.This issue affects Avast/Avg Antivirus: 23.8.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
16/11/2023

CVE-2023-47397

Publication date:
08/11/2023
WeBid
Severity CVSS v4.0: Pending analysis
Last modification:
03/09/2024