Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-2588

Publication date:
18/03/2024
Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/admin/index.php, in the 'id' parameter. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the DB.
Severity CVSS v4.0: Pending analysis
Last modification:
16/04/2025

CVE-2024-27772

Publication date:
18/03/2024
<br /> Unitronics Unistream Unilogic – Versions prior to 1.35.227 -<br /> <br /> CWE-78: &amp;#39;OS Command Injection&amp;#39; may allow RCE<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
10/03/2025

CVE-2024-27773

Publication date:
18/03/2024
<br /> Unitronics Unistream Unilogic – Versions prior to 1.35.227 -<br /> <br /> CWE-348: Use of Less Trusted Source may allow RCE<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
10/03/2025

CVE-2024-27774

Publication date:
18/03/2024
<br /> Unitronics Unistream Unilogic – Versions prior to 1.35.227 -<br /> <br /> CWE-259: Use of Hard-coded Password may allow disclosing Sensitive Information Embedded inside Device&amp;#39;s Firmware<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
10/03/2025

CVE-2024-28537

Publication date:
18/03/2024
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the page parameter of fromNatStaticSetting function.
Severity CVSS v4.0: Pending analysis
Last modification:
13/03/2025

CVE-2024-27767

Publication date:
18/03/2024
<br /> CWE-287: Improper Authentication may allow Authentication Bypass<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
10/03/2025

CVE-2024-27768

Publication date:
18/03/2024
<br /> Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: &amp;#39;Path Traversal&amp;#39; may allow RCE<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
10/03/2025

CVE-2024-27769

Publication date:
18/03/2024
<br /> Unitronics Unistream Unilogic – Versions prior to 1.35.227 - <br /> <br /> CWE-200: Exposure of Sensitive Information to an Unauthorized Actor may allow Taking Ownership Over Devices<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
10/03/2025

CVE-2024-27770

Publication date:
18/03/2024
<br /> Unitronics Unistream Unilogic – Versions prior to 1.35.227 - <br /> <br /> CWE-23: Relative Path Traversal<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
10/03/2025

CVE-2024-27771

Publication date:
18/03/2024
<br /> Unitronics Unistream Unilogic – Versions prior to 1.35.227 -<br /> <br /> CWE-22: &amp;#39;Path Traversal&amp;#39; may allow RCE<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
10/03/2025

CVE-2024-2496

Publication date:
18/03/2024
A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via virConnectListAllInterfaces API. This flaw could be used to perform a denial of service attack by causing the libvirt daemon to crash.
Severity CVSS v4.0: Pending analysis
Last modification:
09/04/2025

CVE-2024-28550

Publication date:
18/03/2024
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the filePath parameter of formExpandDlnaFile function.
Severity CVSS v4.0: Pending analysis
Last modification:
13/03/2025