Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-34031

Publication date:
09/11/2023
Cross-Site Request Forgery (CSRF) vulnerability in Pascal Casier bbPress Toolkit plugin
Severity CVSS v4.0: Pending analysis
Last modification:
15/11/2023

CVE-2023-4379

Publication date:
09/11/2023
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Code owner approval was not removed from merge requests when the target branch was updated.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2024

CVE-2023-5551

Publication date:
09/11/2023
Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.
Severity CVSS v4.0: Pending analysis
Last modification:
17/11/2023

CVE-2023-5546

Publication date:
09/11/2023
ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.
Severity CVSS v4.0: Pending analysis
Last modification:
15/11/2023

CVE-2023-5547

Publication date:
09/11/2023
The course upload preview contained an XSS risk for users uploading unsafe data.
Severity CVSS v4.0: Pending analysis
Last modification:
15/11/2023

CVE-2023-5548

Publication date:
09/11/2023
Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.
Severity CVSS v4.0: Pending analysis
Last modification:
16/11/2023

CVE-2023-5549

Publication date:
09/11/2023
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.
Severity CVSS v4.0: Pending analysis
Last modification:
16/11/2023

CVE-2023-5550

Publication date:
09/11/2023
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
17/11/2023

CVE-2023-5540

Publication date:
09/11/2023
A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.
Severity CVSS v4.0: Pending analysis
Last modification:
16/11/2023

CVE-2023-5541

Publication date:
09/11/2023
The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.
Severity CVSS v4.0: Pending analysis
Last modification:
15/11/2023

CVE-2023-5542

Publication date:
09/11/2023
Students in "Only see own membership" groups could see other students in the group, which should be hidden.
Severity CVSS v4.0: Pending analysis
Last modification:
16/11/2023

CVE-2023-5544

Publication date:
09/11/2023
Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.
Severity CVSS v4.0: Pending analysis
Last modification:
15/11/2023