Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-26263

Publication date:
13/04/2023
All versions of Talend Data Catalog before 8.0-20230110 are potentially vulnerable to XML External Entity (XXE) attacks in the /MIMBWebServices/license endpoint of the remote harvesting server.
Severity CVSS v4.0: Pending analysis
Last modification:
07/02/2025

CVE-2023-26264

Publication date:
13/04/2023
All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks in the license parsing code.
Severity CVSS v4.0: Pending analysis
Last modification:
07/02/2025

CVE-2023-22948

Publication date:
13/04/2023
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is unsecured read access to an SSH private key. Any code that runs as the tigergraph user is able to read the SSH private key. With this, an attacker is granted password-less SSH access to all machines in the TigerGraph cluster.
Severity CVSS v4.0: Pending analysis
Last modification:
07/02/2025

CVE-2022-2445

Publication date:
13/04/2023
Rejected reason: Incorrectly assigned CVE. Not a valid issue.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2023-27772

Publication date:
13/04/2023
libiec61850 v1.5.1 was discovered to contain a segmentation violation via the function ControlObjectClient_setOrigin() at /client/client_control.c.
Severity CVSS v4.0: Pending analysis
Last modification:
07/02/2025

CVE-2023-22950

Publication date:
13/04/2023
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. Data loading jobs in gsql_server, created by any user with designer permissions, can read sensitive data from arbitrary locations.
Severity CVSS v4.0: Pending analysis
Last modification:
07/02/2025

CVE-2023-27779

Publication date:
13/04/2023
AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via the user parameter in the login form.
Severity CVSS v4.0: Pending analysis
Last modification:
07/02/2025

CVE-2023-30630

Publication date:
13/04/2023
Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible. NOTE: Some third parties have indicated the fix in 3.5 does not adequately address the vulnerability. The argument is that the proposed patch prevents dmidecode from writing to an existing file. However, there are multiple attack vectors that would not require overwriting an existing file that would provide the same level of unauthorized privilege escalation (e.g. creating a new file in /etc/cron.hourly).
Severity CVSS v4.0: Pending analysis
Last modification:
04/03/2025

CVE-2023-29598

Publication date:
13/04/2023
lmxcms v1.4.1 was discovered to contain a SQL injection vulnerability via the setbook parameter at index.php.
Severity CVSS v4.0: Pending analysis
Last modification:
07/02/2025

CVE-2023-29597

Publication date:
13/04/2023
bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=1.
Severity CVSS v4.0: Pending analysis
Last modification:
22/12/2023

CVE-2023-27812

Publication date:
13/04/2023
bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.
Severity CVSS v4.0: Pending analysis
Last modification:
22/12/2023

CVE-2023-2021

Publication date:
13/04/2023
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.3.
Severity CVSS v4.0: Pending analysis
Last modification:
21/04/2023