Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-6975

Publication date:
20/12/2023
A malicious user could use this issue to get command execution on the vulnerable machine and get access to data & models information.
Severity CVSS v4.0: Pending analysis
Last modification:
06/02/2024

CVE-2023-6976

Publication date:
20/12/2023
This vulnerability is capable of writing arbitrary files into arbitrary locations on the remote filesystem in the context of the server process.
Severity CVSS v4.0: Pending analysis
Last modification:
29/12/2023

CVE-2023-6977

Publication date:
20/12/2023
This vulnerability enables malicious users to read sensitive files on the server.
Severity CVSS v4.0: Pending analysis
Last modification:
29/12/2023

CVE-2023-47703

Publication date:
20/12/2023
IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 271197.
Severity CVSS v4.0: Pending analysis
Last modification:
22/12/2023

CVE-2023-47705

Publication date:
20/12/2023
IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to manipulate username data due to improper input validation. IBM X-Force ID: 271228.
Severity CVSS v4.0: Pending analysis
Last modification:
22/12/2023

CVE-2023-47707

Publication date:
20/12/2023
IBM Security Guardium Key Lifecycle Manager 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 271522.
Severity CVSS v4.0: Pending analysis
Last modification:
22/12/2023

CVE-2023-47702

Publication date:
20/12/2023
IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view modify files on the system. IBM X-Force ID: 271196.
Severity CVSS v4.0: Pending analysis
Last modification:
22/12/2023

CVE-2023-27172

Publication date:
20/12/2023
Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the secret key used to sign JWT tokens via a bruteforce attack.
Severity CVSS v4.0: Pending analysis
Last modification:
06/05/2025

CVE-2023-47706

Publication date:
20/12/2023
IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of a dangerous file type. IBM X-Force ID: 271341.
Severity CVSS v4.0: Pending analysis
Last modification:
22/12/2023

CVE-2023-47704

Publication date:
20/12/2023
IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other secrets in source code repository. IBM X-Force ID: 271220.
Severity CVSS v4.0: Pending analysis
Last modification:
22/12/2023

CVE-2023-50704

Publication date:
20/12/2023
<br /> <br /> <br /> <br /> <br /> An attacker could construct a URL within the application that causes a redirection to an arbitrary external domain and could be leveraged to facilitate phishing attacks against application users.<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
29/12/2023

CVE-2023-50705

Publication date:
20/12/2023
<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> An attacker could create malicious requests to obtain sensitive information about the web server.<br /> <br /> <br /> <br /> <br /> <br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
29/12/2023