Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-20016

Publication date:
05/02/2024
In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation Patch ID: ALPS07835901; Issue ID: ALPS07835901.
Severity CVSS v4.0: Pending analysis
Last modification:
03/07/2024

CVE-2024-24866

Publication date:
05/02/2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Biteship Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo allows Reflected XSS.This issue affects Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo: from n/a through 2.2.24.
Severity CVSS v4.0: Pending analysis
Last modification:
28/04/2026

CVE-2024-24870

Publication date:
05/02/2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Advanced iFrame allows Stored XSS.This issue affects Advanced iFrame: from n/a through 2023.10.
Severity CVSS v4.0: Pending analysis
Last modification:
28/04/2026

CVE-2023-5677

Publication date:
05/02/2024
Brandon<br /> Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi<br /> did not have a sufficient input validation allowing for a possible remote code<br /> execution. This flaw can only be exploited after authenticating with an<br /> operator- or administrator-privileged service account. The impact of exploiting<br /> this vulnerability is lower with operator-privileges compared to<br /> administrator-privileges service accounts. Please refer to the Axis security advisory<br /> for more information and solution.
Severity CVSS v4.0: Pending analysis
Last modification:
15/05/2025

CVE-2023-5800

Publication date:
05/02/2024
Vintage,<br /> member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi<br /> did not have a sufficient input validation allowing for a possible remote code<br /> execution. This flaw can only be exploited after authenticating with an<br /> operator- or administrator-privileged service account. Axis has released patched AXIS OS<br /> versions for the highlighted flaw. Please refer to the Axis security advisory<br /> for more information and solution.
Severity CVSS v4.0: Pending analysis
Last modification:
08/11/2024

CVE-2023-51504

Publication date:
05/02/2024
Improper Neutralization of Input During Web Page Generation (&amp;#39;Cross-site Scripting&amp;#39;) vulnerability in Dan Dulaney Dan&amp;#39;s Embedder for Google Calendar allows Stored XSS.This issue affects Dan&amp;#39;s Embedder for Google Calendar: from n/a through 1.2.
Severity CVSS v4.0: Pending analysis
Last modification:
28/04/2026

CVE-2023-47170

Publication date:
05/02/2024
Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2023.
Severity CVSS v4.0: Pending analysis
Last modification:
05/02/2024

CVE-2024-25089

Publication date:
04/02/2024
Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes.
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2024

CVE-2021-46902

Publication date:
04/02/2024
An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. Path validation is mishandled, and thus an admin can read or delete files in violation of expected access controls.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2025

CVE-2021-46903

Publication date:
04/02/2024
An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. An admin can delete required user accounts (in violation of expected access control).
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2025

CVE-2023-52425

Publication date:
04/02/2024
libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
Severity CVSS v4.0: Pending analysis
Last modification:
04/11/2025

CVE-2023-52426

Publication date:
04/02/2024
libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.
Severity CVSS v4.0: Pending analysis
Last modification:
04/11/2025