Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-49271

Publication date:
20/12/2023
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_out_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2026

CVE-2023-49270

Publication date:
20/12/2023
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_in_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2026

CVE-2023-23970

Publication date:
20/12/2023
Unrestricted Upload of File with Dangerous Type vulnerability in WooRockets Corsa.This issue affects Corsa: from n/a through 1.5.
Severity CVSS v4.0: Pending analysis
Last modification:
28/04/2026

CVE-2023-25970

Publication date:
20/12/2023
Unrestricted Upload of File with Dangerous Type vulnerability in Zendrop Zendrop – Global Dropshipping.This issue affects Zendrop – Global Dropshipping: from n/a through 1.0.0.
Severity CVSS v4.0: Pending analysis
Last modification:
28/04/2026

CVE-2023-47990

Publication date:
20/12/2023
SQL Injection vulnerability in components/table_manager/html/edit_admin_table.php in CuppaCMS V1.0 allows attackers to run arbitrary SQL commands via the table parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
17/09/2024

CVE-2023-49814

Publication date:
20/12/2023
Unrestricted Upload of File with Dangerous Type vulnerability in Symbiostock symbiostock.This issue affects Symbiostock: from n/a through 6.0.0.
Severity CVSS v4.0: Pending analysis
Last modification:
28/04/2026

CVE-2023-45603

Publication date:
20/12/2023
Unrestricted Upload of File with Dangerous Type vulnerability in Jeff Starr User Submitted Posts – Enable Users to Submit Posts from the Front End.This issue affects User Submitted Posts – Enable Users to Submit Posts from the Front End: from n/a through 20230902.
Severity CVSS v4.0: Pending analysis
Last modification:
28/04/2026

CVE-2023-46149

Publication date:
20/12/2023
Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.
Severity CVSS v4.0: Pending analysis
Last modification:
28/04/2026

CVE-2023-47784

Publication date:
20/12/2023
Unrestricted Upload of File with Dangerous Type vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.6.15.
Severity CVSS v4.0: Pending analysis
Last modification:
28/04/2026

CVE-2023-31231

Publication date:
20/12/2023
Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates).This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.65.
Severity CVSS v4.0: Pending analysis
Last modification:
28/04/2026

CVE-2023-33318

Publication date:
20/12/2023
Unrestricted Upload of File with Dangerous Type vulnerability in WooCommerce AutomateWoo.This issue affects AutomateWoo: from n/a through 4.9.40.
Severity CVSS v4.0: Pending analysis
Last modification:
28/04/2026

CVE-2023-34007

Publication date:
20/12/2023
Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3.
Severity CVSS v4.0: Pending analysis
Last modification:
28/04/2026