Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-23905

Publication date:
24/01/2024
Jenkins Red Hat Dependency Analytics Plugin 0.7.1 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.
Severity CVSS v4.0: Pending analysis
Last modification:
20/06/2025

CVE-2021-42143

Publication date:
24/01/2024
An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. An infinite loop bug exists during the handling of a ClientHello handshake message. This bug allows remote attackers to cause a denial of service by sending a malformed ClientHello handshake message with an odd length of cipher suites, which triggers an infinite loop (consuming all resources) and a buffer over-read that can disclose sensitive information.
Severity CVSS v4.0: Pending analysis
Last modification:
20/06/2025

CVE-2021-42144

Publication date:
24/01/2024
Buffer over-read vulnerability in Contiki-NG tinyDTLS through master branch 53a0d97 allows attackers obtain sensitive information via crafted input to dtls_ccm_decrypt_message().
Severity CVSS v4.0: Pending analysis
Last modification:
20/06/2025

CVE-2023-51888

Publication date:
24/01/2024
Buffer Overflow vulnerability in the nomath() function in Mathtex v.1.05 and before allows a remote attacker to cause a denial of service via a crafted string in the application URL.
Severity CVSS v4.0: Pending analysis
Last modification:
05/09/2024

CVE-2023-51889

Publication date:
24/01/2024
Stack Overflow vulnerability in the validate() function in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in the application URL.
Severity CVSS v4.0: Pending analysis
Last modification:
16/06/2025

CVE-2023-51890

Publication date:
24/01/2024
An infinite loop issue discovered in Mathtex 1.05 and before allows a remote attackers to consume CPU resources via crafted string in the application URL.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2025

CVE-2023-52038

Publication date:
24/01/2024
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.
Severity CVSS v4.0: Pending analysis
Last modification:
30/05/2025

CVE-2023-52039

Publication date:
24/01/2024
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.
Severity CVSS v4.0: Pending analysis
Last modification:
30/05/2025

CVE-2023-52040

Publication date:
24/01/2024
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.
Severity CVSS v4.0: Pending analysis
Last modification:
01/08/2024

CVE-2024-22720

Publication date:
24/01/2024
Kanboard 1.2.34 is vulnerable to Html Injection in the group management feature.
Severity CVSS v4.0: Pending analysis
Last modification:
05/06/2025

CVE-2024-23648

Publication date:
24/01/2024
Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The password reset functionality sends to the the user requesting a password change an email containing an URL to reset its password. The URL sent contains a unique token, valid during 24 hours, allowing the user to reset its password. This token is highly sensitive ; as an attacker able to retrieve it would be able to resets the user's password. Prior to version 1.2.3, the reset-password URL is crafted using the "Host" HTTP header of the request sent to request a password reset. This way, an external attacker could send password requests for users, but specify a "Host" header of a website that they control. If the user receiving the mail clicks on the link, the attacker would retrieve the reset token of the victim and perform account takeover. Version 1.2.3 fixes this issue.
Severity CVSS v4.0: Pending analysis
Last modification:
02/02/2024

CVE-2023-51885

Publication date:
24/01/2024
Buffer Overflow vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via the length of the LaTeX string component.
Severity CVSS v4.0: Pending analysis
Last modification:
30/05/2025