Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-5422

Publication date:
16/10/2023
The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication. As the <br /> SSL_get_verify_result() function is not used the certificated is trusted always and it can not be ensured that the certificate <br /> satisfies all necessary security requirements.<br /> <br /> This could allow an <br /> attacker to use an invalid certificate to claim to be a trusted host, <br /> use expired certificates, or conduct other attacks that could be <br /> detected if the certificate is properly validated.<br /> <br /> This issue affects OTRS: from 7.0.X before 7.0.47, from 8.0.X before 8.0.37; ((OTRS)) Community Edition: from 6.0.X through 6.0.34.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
20/10/2023

CVE-2023-5595

Publication date:
16/10/2023
Denial of Service in GitHub repository gpac/gpac prior to 2.3.0-DEV.
Severity CVSS v4.0: Pending analysis
Last modification:
20/10/2023

CVE-2023-45656

Publication date:
16/10/2023
Cross-Site Request Forgery (CSRF) vulnerability in Kevin Weber Lazy Load for Videos plugin
Severity CVSS v4.0: Pending analysis
Last modification:
19/10/2023

CVE-2023-45757

Publication date:
16/10/2023
Security vulnerability in Apache bRPC 1.6.0, download link: https://dist.apache.org/repos/dist/release/brpc/1.6.1/ <br /> 2. If you are using an old version of bRPC and hard to upgrade, you can apply this patch:  https://github.com/apache/brpc/pull/2411 <br /> 3. disable rpcz feature
Severity CVSS v4.0: Pending analysis
Last modification:
19/10/2023

CVE-2023-4620

Publication date:
16/10/2023
The Booking Calendar WordPress plugin before 9.7.3.1 does not sanitize and escape some of its booking from data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators
Severity CVSS v4.0: Pending analysis
Last modification:
02/05/2025

CVE-2023-4822

Publication date:
16/10/2023
Grafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with several organizations, and allows a user with Organization Admin permissions in one organization to change the permissions associated with Organization Viewer, Organization Editor and Organization Admin roles in all organizations.<br /> <br /> It also allows an Organization Admin to assign or revoke any permissions that they have to any user globally.<br /> <br /> This means that any Organization Admin can elevate their own permissions in any organization that they are already a member of, or elevate or restrict the permissions of any other user.<br /> <br /> The vulnerability does not allow a user to become a member of an organization that they are not already a member of, or to add any other users to an organization that the current user is not a member of.
Severity CVSS v4.0: Pending analysis
Last modification:
16/06/2025

CVE-2023-4827

Publication date:
16/10/2023
The File Manager Pro WordPress plugin before 1.8 does not properly check the CSRF nonce in the `fs_connector` AJAX action. This allows attackers to make highly privileged users perform unwanted file system actions via CSRF attacks by using GET requests, such as uploading a web shell.
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2025

CVE-2023-4834

Publication date:
16/10/2023
In Red Lion Europe mbCONNECT24 and mymbCONNECT24 and Helmholz myREX24 and myREX24.virtual up to and including 2.14.2 an improperly implemented access validation allows an authenticated, low privileged attacker to gain read access to limited, non-critical device information in his account he should not have access to.<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
24/10/2023

CVE-2023-5421

Publication date:
16/10/2023
An attacker who is logged into OTRS as an user with privileges to create and change customer user data may manipulate the CustomerID field to execute JavaScript code that runs <br /> immediatly after the data is saved.The issue onlyoccurs if the configuration for AdminCustomerUser::UseAutoComplete was changed before.<br /> This issue affects OTRS: from 7.0.X before 7.0.47, from 8.0.X before 8.0.37; ((OTRS)) Community Edition: from 6.0.X through 6.0.34.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
19/10/2023

CVE-2023-45638

Publication date:
16/10/2023
Cross-Site Request Forgery (CSRF) vulnerability in euPago Eupago Gateway For Woocommerce plugin
Severity CVSS v4.0: Pending analysis
Last modification:
18/10/2023

CVE-2023-45650

Publication date:
16/10/2023
Cross-Site Request Forgery (CSRF) vulnerability in Fla-shop.Com HTML5 Maps plugin
Severity CVSS v4.0: Pending analysis
Last modification:
18/10/2023

CVE-2023-45651

Publication date:
16/10/2023
Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi WP Attachments allows Cross Site Request Forgery.This issue affects WP Attachments: from n/a through 5.0.11.
Severity CVSS v4.0: Pending analysis
Last modification:
11/07/2024