Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-14740

Publication date:
30/07/2018
An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in set_field_one in bootstrap.c while making a query.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-14741

Publication date:
30/07/2018
An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in pbc_pattern_pack in pattern.c.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-14742

Publication date:
30/07/2018
An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in set_field_one in bootstrap.c during a memcpy.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-14743

Publication date:
30/07/2018
An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in wiretype_decode in context.c.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-14734

Publication date:
29/07/2018
drivers/infiniband/core/ucma.c in the Linux kernel through 4.17.11 allows ucma_leave_multicast to access a certain data structure after a cleanup step in ucma_process_join, which allows attackers to cause a denial of service (use-after-free).
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-14679

Publication date:
28/07/2018
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and application crash).
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-14680

Publication date:
28/07/2018
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-14681

Publication date:
28/07/2018
An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-14682

Publication date:
28/07/2018
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-14685

Publication date:
28/07/2018
The add function in www/Lib/Lib/Action/Admin/TplAction.class.php in Gxlcms v1.1.4 allows remote attackers to read arbitrary files via a crafted index.php?s=Admin-Tpl-ADD-id request, related to Lib/Common/Admin/function.php.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-14686

Publication date:
28/07/2018
system/edit_book.php in XYCMS 1.7 has stored XSS via a crafted add_do.php request, related to add_book.php.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-14678

Publication date:
28/07/2018
An issue was discovered in the Linux kernel through 4.17.11, as used in Xen through 4.11.x. The xen_failsafe_callback entry point in arch/x86/entry/entry_64.S does not properly maintain RBX, which allows local users to cause a denial of service (uninitialized memory usage and system crash). Within Xen, 64-bit x86 PV Linux guest OS users can trigger a guest OS crash or possibly gain privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026