Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2016-3690

Publication date:
08/06/2017
The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2016-2034

Publication date:
08/06/2017
SQL injection vulnerability in ClearPass Policy Manager 6.5.x through 6.5.6 and 6.6.0.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2016-3091

Publication date:
08/06/2017
Cloud Foundry Diego 0.1468.0 through 0.1470.0 allows remote attackers to cause a denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2016-4471

Publication date:
08/06/2017
ManageIQ in CloudForms before 4.1 allows remote authenticated users to execute arbitrary code.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2016-3107

Publication date:
08/06/2017
The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/pki/pulp/nodes/" directory, which allows local users to gain access to sensitive data.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2016-3108

Publication date:
08/06/2017
The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attack.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2016-4457

Publication date:
08/06/2017
CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2014-3498

Publication date:
08/06/2017
The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2016-3111

Publication date:
08/06/2017
pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp consumers in a directory that is world-readable before later modifying the permissions, which might allow local users to read the generated RSA keys via reading the key files while the installation process is running.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2016-3112

Publication date:
08/06/2017
client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which allows remote authenticated users to obtain the consumer private keys and escalate privileges by reading /etc/pki/pulp/consumer/consumer-cert, and authenticating as a consumer user.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2015-2800

Publication date:
08/06/2017
The user authentication module in Huawei Campus switches S5700, S5300, S6300, and S6700 with software before V200R001SPH012 and S7700, S9300, and S9700 with software before V200R001SPH015 allows remote attackers to cause a denial of service (device restart) via vectors involving authentication, which trigger an array access violation.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2015-2252

Publication date:
08/06/2017
Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to execute arbitrary code with root privileges via a crafted UDS patch with shell scripts.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025