Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-35991

Publication date:
18/08/2023
Hidden functionality vulnerability in LOGITEC wireless LAN routers allows an unauthenticated attacker to log in to the product's certain management console and execute arbitrary OS commands. Affected products and versions are as follows: LAN-W300N/DR all versions, LAN-WH300N/DR all versions, LAN-W300N/P all versions, LAN-WH450N/GP all versions, LAN-WH300AN/DGP all versions, LAN-WH300N/DGP all versions, and LAN-WH300ANDGPE all versions.
Severity CVSS v4.0: Pending analysis
Last modification:
21/10/2024

CVE-2023-32626

Publication date:
18/08/2023
Hidden functionality vulnerability in LAN-W300N/RS all versions, and LAN-W300N/PR5 all versions allows an unauthenticated attacker to log in to the product's certain management console and execute arbitrary OS commands.
Severity CVSS v4.0: Pending analysis
Last modification:
08/10/2024

CVE-2023-30875

Publication date:
18/08/2023
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in All My Web Needs Logo Scheduler plugin
Severity CVSS v4.0: Pending analysis
Last modification:
23/08/2023

CVE-2023-4040

Publication date:
18/08/2023
The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eh_callback_handler function in versions up to, and including, 3.7.9. This makes it possible for unauthenticated attackers to modify the order status of arbitrary WooCommerce orders.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-39674

Publication date:
18/08/2023
D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function fgets.
Severity CVSS v4.0: Pending analysis
Last modification:
25/08/2023

CVE-2023-39673

Publication date:
18/08/2023
Tenda AC15 V1.0BR_V15.03.05.18_multi_TD01 was discovered to contain a buffer overflow via the function FUN_00010e34().
Severity CVSS v4.0: Pending analysis
Last modification:
23/08/2023

CVE-2023-39672

Publication date:
18/08/2023
Tenda WH450 v1.0.0.18 was discovered to contain a buffer overflow via the function fgets.
Severity CVSS v4.0: Pending analysis
Last modification:
23/08/2023

CVE-2023-39671

Publication date:
18/08/2023
D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function FUN_0001be68.
Severity CVSS v4.0: Pending analysis
Last modification:
25/08/2023

CVE-2023-39667

Publication date:
18/08/2023
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the FUN_0000acb4 function.
Severity CVSS v4.0: Pending analysis
Last modification:
02/08/2024

CVE-2023-39669

Publication date:
18/08/2023
D-Link DIR-880 A1_FW107WWb08 was discovered to contain a NULL pointer dereference in the function FUN_00010824.
Severity CVSS v4.0: Pending analysis
Last modification:
25/08/2023

CVE-2023-39668

Publication date:
18/08/2023
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the inet_ntoa() function.
Severity CVSS v4.0: Pending analysis
Last modification:
02/08/2024

CVE-2023-39670

Publication date:
18/08/2023
Tenda AC6 _US_AC6V1.0BR_V15.03.05.16 was discovered to contain a buffer overflow via the function fgets.
Severity CVSS v4.0: Pending analysis
Last modification:
23/08/2023