Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-3874

Publication date:
25/07/2023
A vulnerability, which was classified as critical, was found in Campcodes Beauty Salon Management System 1.0. Affected is an unknown function of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235236.
Severity CVSS v4.0: Pending analysis
Last modification:
17/05/2024

CVE-2023-33777

Publication date:
25/07/2023
An issue in /functions/fbaorder.php of Prestashop amazon before v5.2.24 allows attackers to execute a directory traversal attack.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2023

CVE-2023-25074

Publication date:
25/07/2023
<br /> Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Competencies.<br /> <br /> <br /> <br /> <br /> <br /> <br /> This issue affects Command Centre: vEL8.90 prior to vEL8.90.1318 (MR1), vEL8.80 prior to vEL8.80.1192 (MR2), vEL8.70 prior to vEL8.70.2185 (MR4), <br /> <br /> vEL8.60 prior to vEL8.60.2347 (MR6),<br /> <br /> vEL8.50 prior to vEL8.50.2831 (MR8), all versions vEL8.40 and prior.<br /> <br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
01/08/2023

CVE-2023-22363

Publication date:
25/07/2023
<br /> A stack-based buffer overflow in the Command Centre Server allows an attacker to cause a denial of service attack via assigning cardholders to an Access Group.<br /> <br /> This issue affects Command Centre: vEL8.80 prior to vEL8.80.1192 (MR2)<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
01/08/2023

CVE-2023-3873

Publication date:
25/07/2023
A vulnerability, which was classified as critical, has been found in Campcodes Beauty Salon Management System 1.0. This issue affects some unknown processing of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235235.
Severity CVSS v4.0: Pending analysis
Last modification:
17/05/2024

CVE-2023-22428

Publication date:
24/07/2023
<br /> Improper privilege validation in Command Centre Server allows authenticated operators to modify Division lineage.<br /> <br /> This issue affects Command Centre: vEL8.80 prior to vEL8.80.1192 (MR2), vEL8.70 prior to vEL8.70.2185 (MR4), vEL8.60 prior to vEL8.60.2347 (MR6), vEL8.50 prior to vEL8.50.2831(MR8), vEL8.40 and prior.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
01/08/2023

CVE-2023-3871

Publication date:
24/07/2023
A vulnerability classified as critical has been found in Campcodes Beauty Salon Management System 1.0. This affects an unknown part of the file /admin/edit_category.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235233 was assigned to this vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
17/05/2024

CVE-2023-3872

Publication date:
24/07/2023
A vulnerability classified as critical was found in Campcodes Beauty Salon Management System 1.0. This vulnerability affects unknown code of the file /admin/edit-services.php. The manipulation of the argument editid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235234 is the identifier assigned to this vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
17/05/2024

CVE-2023-26045

Publication date:
24/07/2023
NodeBB is Node.js based forum software. Starting in version 2.5.0 and prior to version 2.8.7, due to the use of the object destructuring assignment syntax in the user export code path, combined with a path traversal vulnerability, a specially crafted payload could invoke the user export logic to arbitrarily execute javascript files on the local disk. This issue is patched in version 2.8.7. As a workaround, site maintainers can cherry pick the fix into their codebase to patch the exploit.
Severity CVSS v4.0: Pending analysis
Last modification:
31/08/2023

CVE-2023-20593

Publication date:
24/07/2023
An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.
Severity CVSS v4.0: Pending analysis
Last modification:
13/02/2025

CVE-2021-39421

Publication date:
24/07/2023
A cross-site scripting (XSS) vulnerability in SeedDMS v6.0.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-34478

Publication date:
24/07/2023
Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests.<br /> <br /> Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+
Severity CVSS v4.0: Pending analysis
Last modification:
13/02/2025