Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-6928

Publication date:
13/02/2018
PHP Scripts Mall News Website Script 2.0.4 has SQL Injection via a search term.
Severity CVSS v4.0: Pending analysis
Last modification:
07/03/2018

CVE-2018-0488

Publication date:
13/02/2018
ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption) via a crafted application packet within a TLS or DTLS session.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2018-0487

Publication date:
13/02/2018
ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted certificate chain that is mishandled during RSASSA-PSS signature verification within a TLS or DTLS session.
Severity CVSS v4.0: Pending analysis
Last modification:
10/02/2020

CVE-2018-6911

Publication date:
13/02/2018
The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argument (aka the command parameter).
Severity CVSS v4.0: Pending analysis
Last modification:
02/08/2019

CVE-2018-6292

Publication date:
13/02/2018
Remote Code Execution in Saperion Web Client version 7.5.2 83166.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-6293

Publication date:
13/02/2018
Arbitrary File Read in Saperion Web Client version 7.5.2 83166.
Severity CVSS v4.0: Pending analysis
Last modification:
06/03/2018

CVE-2018-1297

Publication date:
13/02/2018
When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2018-6942

Publication date:
13/02/2018
An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within ttinterp.c could lead to DoS via a crafted font file.
Severity CVSS v4.0: Pending analysis
Last modification:
26/01/2021

CVE-2018-6930

Publication date:
13/02/2018
A stack-based buffer over-read in the ComputeResizeImage function in the MagickCore/accelerate.c file of ImageMagick 7.0.7-22 allows a remote attacker to cause a denial of service (application crash) via a maliciously crafted pict file.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2017-9963

Publication date:
12/02/2018
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type of attack requires some level of social engineering in order to get a legitimate user to click on or access a malicious link/site containing the CSRF attack.
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2019

CVE-2017-9967

Publication date:
12/02/2018
A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software versions 12 and prior. Security configuration settings such as Address Space Layout Randomization (ASLR) and Data Execution prevention (DEP) were not properly configured resulting in weak security.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2017-9969

Publication date:
12/02/2018
An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. Passwords are stored in clear text in the configuration which can result in exposure of sensitive information.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019