Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2017-16022

Publication date:
04/06/2018
Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not escaped in versions 0.5.0 and earlier. If control over the labels is obtained, script can be injected. The script will run on the client side whenever that specific graph is loaded.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-16023

Publication date:
04/06/2018
Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1 uses regular expressions to evaluate a string and takes unescaped separator values, which can be used to create a denial of service attack.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-16024

Publication date:
04/06/2018
The sync-exec module is used to simulate child_process.execSync in node versions
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-16025

Publication date:
04/06/2018
Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denial of service vulnerability via an invalid Cookie header. This is only present when websocket authentication is set to `cookie`. Submitting an invalid cookie on the websocket upgrade request will cause the node process to error out.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-16026

Publication date:
04/06/2018
Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the specified number of non-zero memory is passed in the body. This affects Request >=2.2.6 2.51.0
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-16028

Publication date:
04/06/2018
react-native-meteor-oauth is a library for Oauth2 login to a Meteor server in React Native. The oauth Random Token is generated using a non-cryptographically strong RNG (Math.random()).
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-16029

Publication date:
04/06/2018
hostr is a simple web server that serves up the contents of the current directory. There is a directory traversal vulnerability in hostr 2.3.5 and earlier that allows an attacker to read files outside the current directory by sending `../` in the url path for GET requests.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-16030

Publication date:
04/06/2018
Useragent is used to parse useragent headers. It uses several regular expressions to accomplish this. An attacker could edit their own headers, creating an arbitrarily long useragent string, causing the event loop and server to block. This affects Useragent 2.1.12 and earlier.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-16031

Publication date:
04/06/2018
Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on `Math.random()` to create socket IDs, the IDs are predictable. An attacker is able to guess the socket ID and gain access to socket.io servers, potentially obtaining sensitive information.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-16035

Publication date:
04/06/2018
The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.com. It appears in the code that these files are downloaded over HTTPS however the api.hubapi.com endpoint redirects to a HTTP url. Because of this behavior an attacker with the ability to man-in-the-middle a developer or system performing a package installation could compromise the integrity of the installation.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-16036

Publication date:
04/06/2018
`badjs-sourcemap-server` receives files sent by `badjs-sourcemap`. `badjs-sourcemap-server` is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-16037

Publication date:
04/06/2018
`gomeplus-h5-proxy` is vulnerable to a directory traversal issue, allowing attackers to access any file in the system by placing '../' in the URL.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026