Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2013-7234

Publication date:
29/04/2014
Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to conduct clickjacking attacks via an X-Frame-Options header.
Severity CVSS v4.0: Pending analysis
Last modification:
12/04/2025

CVE-2013-7235

Publication date:
29/04/2014
Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to impersonate arbitrary users via multiple space characters characters.
Severity CVSS v4.0: Pending analysis
Last modification:
12/04/2025

CVE-2013-7236

Publication date:
29/04/2014
Simple Machines Forum (SMF) 2.0.6, 1.1.19, and earlier allows remote attackers to impersonate arbitrary users via a Unicode homoglyph character in a username.
Severity CVSS v4.0: Pending analysis
Last modification:
12/04/2025

CVE-2013-7259

Publication date:
29/04/2014
Multiple cross-site request forgery (CSRF) vulnerabilities in Neo4J 1.9.2 allow remote attackers to hijack the authentication of administrators for requests that execute arbitrary code, as demonstrated by a request to (1) db/data/ext/GremlinPlugin/graphdb/execute_script or (2) db/manage/server/console/.
Severity CVSS v4.0: Pending analysis
Last modification:
12/04/2025

CVE-2013-7111

Publication date:
29/04/2014
The put_call function in the API client (api/api_client.rb) in the BaseSpace Ruby SDK (aka bio-basespace-sdk) gem 0.1.7 for Ruby uses the API_KEY on the command line, which allows remote attackers to obtain sensitive information by listing the processes.
Severity CVSS v4.0: Pending analysis
Last modification:
12/04/2025

CVE-2013-7134

Publication date:
29/04/2014
Juvia uses the same secret key for all installations, which allows remote attackers to have unspecified impact by leveraging the secret key in app/config/initializers/secret_token.rb, related to cookies.
Severity CVSS v4.0: Pending analysis
Last modification:
12/04/2025

CVE-2013-7220

Publication date:
29/04/2014
js/ui/screenShield.js in GNOME Shell (aka gnome-shell) before 3.8 allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation with the keyboard focus on the Activities search.
Severity CVSS v4.0: Pending analysis
Last modification:
12/04/2025

CVE-2013-7063

Publication date:
29/04/2014
The Invitation module 7.x-2.x for Drupal does not properly check permissions, which allows remote attackers to obtain sensitive information via unspecified default views.
Severity CVSS v4.0: Pending analysis
Last modification:
12/04/2025

CVE-2013-7064

Publication date:
29/04/2014
Cross-site scripting (XSS) vulnerability in the EU Cookie Compliance module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated administrators with the "Administer EU Cookie Compliance popup" permission to inject arbitrary web script or HTML via unspecified configuration values.
Severity CVSS v4.0: Pending analysis
Last modification:
12/04/2025

CVE-2013-7066

Publication date:
29/04/2014
The Entity reference module 7.x-1.x before 7.x-1.1-rc1 for Drupal allows remote attackers to read private nodes titles by leveraging edit permissions to a node that references a private node.
Severity CVSS v4.0: Pending analysis
Last modification:
12/04/2025

CVE-2013-7068

Publication date:
29/04/2014
The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users to bypass group restrictions on nodes with all groups set to optional input via an empty group field.
Severity CVSS v4.0: Pending analysis
Last modification:
12/04/2025

CVE-2013-7065

Publication date:
29/04/2014
The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote attackers to bypass access restrictions and post to arbitrary groups via a group audience field, as demonstrated by the og_group_ref field.
Severity CVSS v4.0: Pending analysis
Last modification:
12/04/2025