Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2014-6106

Publication date:
18/09/2017
Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1, 6.0, and 7.0 allows remote attackers to hijack the authentication of users for requests that can cause cross-site scripting attacks, web cache poisoning, or other unspecified impacts via unknown vectors.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-9798

Publication date:
18/09/2017
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27. The attacker sends an unauthenticated OPTIONS HTTP request when attempting to read secret data. This is a use-after-free issue and thus secret data is not always sent, and the specific data depends on many factors including configuration. Exploitation with .htaccess can be blocked with a patch to the ap_limit_section function in server/core.c.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-14534

Publication date:
18/09/2017
Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to location.php, related to PHP_SELF.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-12156

Publication date:
18/09/2017
Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-12157

Publication date:
18/09/2017
In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-14530

Publication date:
18/09/2017
WP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7 for WordPress has CSRF via the name parameter in an action=manage&do=create operation, as demonstrated by inserting XSS sequences.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-14531

Publication date:
18/09/2017
ImageMagick 7.0.7-0 has a memory exhaustion issue in ReadSUNImage in coders/sun.c.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-14532

Publication date:
18/09/2017
ImageMagick 7.0.7-0 has a NULL Pointer Dereference in TIFFIgnoreTags in coders/tiff.c.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-14533

Publication date:
18/09/2017
ImageMagick 7.0.6-6 has a memory leak in ReadMATImage in coders/mat.c.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-9333

Publication date:
18/09/2017
OpenWebif 1.2.5 allows remote code execution via a URL to the CallOPKG function in the IpkgController class in plugin/controllers/ipkg.py, when the URL refers to an attacker-controlled web site with a Trojan horse package. This has security implications in cases where untrusted users can trigger CallOPKG calls, and these users can enter an arbitrary URL in an input field, even though that input field was only intended for a package name. This threat model may be relevant in the latest versions of third-party products that bundle OpenWebif, i.e., set-top box products. The issue of Trojan horse packages does NOT have security implications in cases where the attacker has full OpenWebif access.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-14528

Publication date:
18/09/2017
The TIFFSetProfiles function in coders/tiff.c in ImageMagick 7.0.6 has incorrect expectations about whether LibTIFF TIFFGetField return values imply that data validation has occurred, which allows remote attackers to cause a denial of service (use-after-free after an invalid call to TIFFSetField, and application crash) via a crafted file.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-14529

Publication date:
18/09/2017
The pe_print_idata function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles HintName vector entries, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted PE file, related to the bfd_getl16 function.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026