Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-46198

Publication date:
25/10/2023
Cross-Site Request Forgery (CSRF) vulnerability in Scientech It Solution Appointment Calendar plugin
Severity CVSS v4.0: Pending analysis
Last modification:
01/11/2023

CVE-2023-46202

Publication date:
25/10/2023
Cross-Site Request Forgery (CSRF) vulnerability in Jeff Sherk Auto Login New User After Registration plugin
Severity CVSS v4.0: Pending analysis
Last modification:
01/11/2023

CVE-2023-46204

Publication date:
25/10/2023
Cross-Site Request Forgery (CSRF) vulnerability in Muller Digital Inc. Duplicate Theme plugin
Severity CVSS v4.0: Pending analysis
Last modification:
01/11/2023

CVE-2023-46316

Publication date:
25/10/2023
In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3, the wrapper scripts do not properly parse command lines.
Severity CVSS v4.0: Pending analysis
Last modification:
03/07/2024

CVE-2023-46346

Publication date:
25/10/2023
In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 4.1.1 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a path traversal to view all files on the information system.
Severity CVSS v4.0: Pending analysis
Last modification:
11/09/2024

CVE-2023-46347

Publication date:
25/10/2023
In the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL injection. The method `NdkSpack::getPacks()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
Severity CVSS v4.0: Pending analysis
Last modification:
11/09/2024

CVE-2023-46358

Publication date:
25/10/2023
In the module "Referral and Affiliation Program" (referralbyphone) version 3.5.1 and before from Snegurka for PrestaShop, a guest can perform SQL injection. Method `ReferralByPhoneDefaultModuleFrontController::ajaxProcessCartRuleValidate` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
Severity CVSS v4.0: Pending analysis
Last modification:
01/11/2023

CVE-2023-46369

Publication date:
25/10/2023
Tenda W18E V16.01.0.8(1576) contains a stack overflow vulnerability via the portMirrorMirroredPorts parameter in the formSetNetCheckTools function.
Severity CVSS v4.0: Pending analysis
Last modification:
11/09/2024

CVE-2023-46370

Publication date:
25/10/2023
Tenda W18E V16.01.0.8(1576) has a command injection vulnerability via the hostName parameter in the formSetNetCheckTools function.
Severity CVSS v4.0: Pending analysis
Last modification:
01/11/2023

CVE-2023-46371

Publication date:
25/10/2023
TP-Link device TL-WDR7660 2.0.30 and TL-WR886N 2.0.12 has a stack overflow vulnerability via the function upgradeInfoJsonToBin.
Severity CVSS v4.0: Pending analysis
Last modification:
11/09/2024

CVE-2023-46373

Publication date:
25/10/2023
TP-Link TL-WDR7660 2.0.30 has a stack overflow vulnerability via the function deviceInfoJsonToBincauses.
Severity CVSS v4.0: Pending analysis
Last modification:
01/11/2023

CVE-2023-46396

Publication date:
25/10/2023
Audimex 15.0.0 is vulnerable to Cross Site Scripting (XSS) in /audimex/cgi-bin/wal.fcgi via company parameter search filters.
Severity CVSS v4.0: Pending analysis
Last modification:
02/11/2023