Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2014-0128

Publication date:
14/04/2014
Squid 3.1 before 3.3.12 and 3.4 before 3.4.4, when SSL-Bump is enabled, allows remote attackers to cause a denial of service (assertion failure) via a crafted range request, related to state management.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2014-0159

Publication date:
14/04/2014
Buffer overflow in the GetStatistics64 remote procedure call (RPC) in OpenAFS 1.4.8 before 1.6.7 allows remote attackers to cause a denial of service (crash) via a crafted statsVersion argument.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2013-2828

Publication date:
12/04/2014
The DNP Master Driver in the OSIsoft PI Interface before 3.1.2.54 for DNP3 allows physically proximate attackers to cause a denial of service (interface shutdown) via crafted input over a serial line.
Severity CVSS v4.0: Pending analysis
Last modification:
06/05/2026

CVE-2014-0347

Publication date:
12/04/2014
The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix 31, and Web Security Gateway Anywhere 7.7.3 before Hotfix 31 allows remote authenticated users to read cleartext passwords by replacing type="password" with type="text" in an INPUT element in the (1) Log Database or (2) User Directories component.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2014-0349

Publication date:
12/04/2014
Multiple unspecified vulnerabilities in J2k-Codec allow remote attackers to execute arbitrary code via a crafted JPEG 2000 file.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2014-0763

Publication date:
12/04/2014
An attacker using SQL injection may use arguments to construct queries <br /> without proper sanitization. The DBVisitor.dll is exposed through SOAP <br /> interfaces, and the exposed functions are vulnerable to SOAP injection. <br /> This may allow unexpected SQL action and access to records in the table <br /> of the software database or execution of arbitrary code.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2014-0764

Publication date:
12/04/2014
By providing an overly long string to the NodeName parameter, an <br /> attacker may be able to overflow the static stack buffer. The attacker <br /> may then execute code on the target device remotely.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2014-0765

Publication date:
12/04/2014
To exploit this vulnerability, the attacker sends data from the GotoCmd <br /> argument to control. If the value of the argument is overly long, the <br /> static stack buffer can be overflowed. This will allow the attacker to <br /> execute arbitrary code remotely.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2014-0766

Publication date:
12/04/2014
An attacker can exploit this vulnerability by copying an overly long <br /> NodeName2 argument into a statically sized buffer on the stack to <br /> overflow the static stack buffer. An attacker may use this vulnerability<br /> to remotely execute arbitrary code.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2014-0767

Publication date:
12/04/2014
An attacker may exploit this vulnerability by passing an overly long <br /> value from the AccessCode argument to the control. This will overflow <br /> the static stack buffer. The attacker may then execute code on the <br /> target device remotely.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2014-0768

Publication date:
12/04/2014
An attacker may pass an overly long value from the AccessCode2 argument <br /> to the control to overflow the static stack buffer. The attacker may <br /> then remotely execute arbitrary code.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2014-0770

Publication date:
12/04/2014
By providing an overly long string to the UserName parameter, an <br /> attacker may be able to overflow the static stack buffer. The attacker <br /> may then execute code on the target device remotely.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026