Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2023-0319

Fecha de publicación:
05/04/2023
Idioma:
Inglés
*** Pendiente de traducción *** An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1, allowing to read environment names supposed to be restricted to project memebers only.
Gravedad CVSS v3.1: MEDIA
Última modificación:
11/02/2025

CVE-2023-0523

Fecha de publicación:
05/04/2023
Idioma:
Inglés
*** Pendiente de traducción *** An issue has been discovered in GitLab affecting all versions starting from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. An XSS was possible via a malicious email address for certain instances.
Gravedad CVSS v3.1: MEDIA
Última modificación:
10/02/2025

CVE-2023-1098

Fecha de publicación:
05/04/2023
Idioma:
Inglés
*** Pendiente de traducción *** An information disclosure vulnerability has been discovered in GitLab EE/CE affecting all versions starting from 11.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 will allow an admin to leak password from repository mirror configuration.
Gravedad CVSS v3.1: MEDIA
Última modificación:
10/02/2025

CVE-2023-24720

Fecha de publicación:
05/04/2023
Idioma:
Inglés
*** Pendiente de traducción *** An arbitrary file upload vulnerability in readium-js v0.32.0 allows attackers to execute arbitrary code via uploading a crafted EPUB file.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
11/02/2025

CVE-2023-24747

Fecha de publicación:
05/04/2023
Idioma:
Inglés
*** Pendiente de traducción *** Jfinal CMS v5.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/dict/list.
Gravedad CVSS v3.1: MEDIA
Última modificación:
13/02/2025

CVE-2023-0944

Fecha de publicación:
05/04/2023
Idioma:
Inglés
*** Pendiente de traducción *** Bhima version 1.27.0 allows an authenticated attacker with regular user permissions to update arbitrary user session data such as username, email and password. This is possible because the application is vulnerable to IDOR, it does not correctly validate user permissions with respect to certain actions that can be performed by the user.
Gravedad CVSS v3.1: MEDIA
Última modificación:
13/02/2025

CVE-2023-0959

Fecha de publicación:
05/04/2023
Idioma:
Inglés
*** Pendiente de traducción *** Bhima version 1.27.0 allows a remote attacker to update the privileges of any account registered in the application via a malicious link sent to an administrator. This is possible because the application is vulnerable to CSRF.
Gravedad CVSS v3.1: MEDIA
Última modificación:
13/02/2025

CVE-2023-0967

Fecha de publicación:
05/04/2023
Idioma:
Inglés
*** Pendiente de traducción *** Bhima version 1.27.0 allows an attacker authenticated with normal user permissions to view sensitive data of other application users and data that should only be viewed by the administrator. This is possible because the application is vulnerable to IDOR, it does not properly validate user permissions with respect to certain actions the user can perform.
Gravedad CVSS v3.1: MEDIA
Última modificación:
13/02/2025

CVE-2023-1855

Fecha de publicación:
05/04/2023
Idioma:
Inglés
*** Pendiente de traducción *** A use-after-free flaw was found in xgene_hwmon_remove in drivers/hwmon/xgene-hwmon.c in the Hardware Monitoring Linux Kernel Driver (xgene-hwmon). This flaw could allow a local attacker to crash the system due to a race problem. This vulnerability could even lead to a kernel information leak problem.
Gravedad CVSS v3.1: MEDIA
Última modificación:
12/02/2025

CVE-2023-20144

Fecha de publicación:
05/04/2023
Idioma:
Inglés
*** Pendiente de traducción *** Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device and then persuading a user to visit specific web pages that include malicious payloads. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. Cisco has not released software updates that address these vulnerabilities.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/11/2023

CVE-2023-20145

Fecha de publicación:
05/04/2023
Idioma:
Inglés
*** Pendiente de traducción *** Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device and then persuading a user to visit specific web pages that include malicious payloads. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. Cisco has not released software updates that address these vulnerabilities.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/11/2023

CVE-2023-20146

Fecha de publicación:
05/04/2023
Idioma:
Inglés
*** Pendiente de traducción *** Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device and then persuading a user to visit specific web pages that include malicious payloads. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. Cisco has not released software updates that address these vulnerabilities.
Gravedad CVSS v3.1: MEDIA
Última modificación:
07/11/2023