Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-13227

Publication date:
04/07/2019
In GUI mode, deepin-clone before 1.1.3 creates a log file at the fixed path /tmp/.deepin-clone.log as root, and follows symlinks there. An unprivileged user can prepare a symlink attack there to create or overwrite files in arbitrary file system locations. The content is not attacker controlled.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-13228

Publication date:
04/07/2019
deepin-clone before 1.1.3 uses a fixed path /tmp/repo.iso in the BootDoctor::fix() function to download an ISO file, and follows symlinks there. An unprivileged user can prepare a symlink attack there to create or overwrite files in arbitrary file system locations. The content is not attacker controlled. By winning a race condition to replace the /tmp/repo.iso symlink by an attacker controlled ISO file, further privilege escalation may be possible.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-13229

Publication date:
04/07/2019
deepin-clone before 1.1.3 uses a fixed path /tmp/partclone.log in the Helper::getPartitionSizeInfo() function to write a log file as root, and follows symlinks there. An unprivileged user can prepare a symlink attack there to create or overwrite files in arbitrary file system locations. The content is not attacker controlled.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-13208

Publication date:
03/07/2019
WavesSysSvc in Waves MAXX Audio allows privilege escalation because the General registry key has Full Control access for the Users group, leading to DLL side loading. This affects WavesSysSvc64.exe 1.9.29.0.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2015-3907

Publication date:
03/07/2019
CodeIgniter Rest Server (aka codeigniter-restserver) 2.7.1 allows XXE attacks.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-13074

Publication date:
03/07/2019
A vulnerability in the FTP daemon on MikroTik routers through 6.44.3 could allow remote attackers to exhaust all available memory, causing the device to reboot because of uncontrolled resource management.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-9827

Publication date:
03/07/2019
Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-12841

Publication date:
03/07/2019
Incorrect handling of user input in ZIP extraction was detected in JetBrains TeamCity. The issue was fixed in TeamCity 2018.2.2.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-12842

Publication date:
03/07/2019
A reflected XSS on a user page was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.2.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-12843

Publication date:
03/07/2019
A possible stored JavaScript injection requiring a deliberate server administrator action was detected. The issue was fixed in JetBrains TeamCity 2018.2.3.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-12844

Publication date:
03/07/2019
A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-12845

Publication date:
03/07/2019
The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts. The issue was fixed in JetBrains TeamCity 2018.2.3.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026