Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2023-31478

Fecha de publicación:
09/05/2023
Idioma:
Inglés
*** Pendiente de traducción *** An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and key.
Gravedad CVSS v3.1: ALTA
Última modificación:
29/01/2025

CVE-2023-28317

Fecha de publicación:
09/05/2023
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability has been discovered in Rocket.Chat, where editing messages can change the original timestamp, causing the UI to display messages in an incorrect order.
Gravedad CVSS v3.1: MEDIA
Última modificación:
28/01/2025

CVE-2023-28318

Fecha de publicación:
09/05/2023
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory or Message_ShowDeletedStatus server configuration. This allows users to bypass the intended message deletion behavior, hiding messages and deletion notices.
Gravedad CVSS v3.1: MEDIA
Última modificación:
28/01/2025

CVE-2023-2156

Fecha de publicación:
09/05/2023
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the system.
Gravedad CVSS v3.1: ALTA
Última modificación:
03/02/2024

CVE-2023-2610

Fecha de publicación:
09/05/2023
Idioma:
Inglés
*** Pendiente de traducción *** Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1532.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/06/2026

CVE-2023-28127

Fecha de publicación:
09/05/2023
Idioma:
Inglés
*** Pendiente de traducción *** A path traversal vulnerability exists in Avalanche version 6.3.x and below that when exploited could result in possible information disclosure.
Gravedad CVSS v3.1: ALTA
Última modificación:
28/01/2025

CVE-2023-28126

Fecha de publicación:
09/05/2023
Idioma:
Inglés
*** Pendiente de traducción *** An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message.
Gravedad CVSS v3.1: MEDIA
Última modificación:
29/01/2025

CVE-2023-28125

Fecha de publicación:
09/05/2023
Idioma:
Inglés
*** Pendiente de traducción *** An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attacker to gain access to the server by registering to receive messages from the server and perform an authentication bypass.
Gravedad CVSS v3.1: MEDIA
Última modificación:
29/01/2025

CVE-2023-28316

Fecha de publicación:
09/05/2023
Idioma:
Inglés
*** Pendiente de traducción *** A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not invalidated upon activating 2FA. This could potentially allow an attacker to maintain access to a compromised account even after 2FA is enabled.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
28/01/2025

CVE-2023-28128

Fecha de publicación:
09/05/2023
Idioma:
Inglés
*** Pendiente de traducción *** An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution.
Gravedad CVSS v3.1: ALTA
Última modificación:
28/01/2025

CVE-2023-25831

Fecha de publicación:
09/05/2023
Idioma:
Inglés
*** Pendiente de traducción *** There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/04/2025

CVE-2023-25832

Fecha de publicación:
09/05/2023
Idioma:
Inglés
*** Pendiente de traducción *** There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.0 and below that may allow an attacker to trick an authorized user into executing unwanted actions.
Gravedad CVSS v3.1: ALTA
Última modificación:
01/02/2024