Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-41527

Publication date:
06/10/2022
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the pppoeUser parameter in the setOpModeCfg function.
Severity CVSS v4.0: Pending analysis
Last modification:
12/10/2022

CVE-2022-41528

Publication date:
06/10/2022
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function.
Severity CVSS v4.0: Pending analysis
Last modification:
12/10/2022

CVE-2022-41525

Publication date:
06/10/2022
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the OpModeCfg function at /cgi-bin/cstecgi.cgi.
Severity CVSS v4.0: Pending analysis
Last modification:
08/08/2023

CVE-2022-41522

Publication date:
06/10/2022
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an unauthenticated stack overflow via the "main" function.
Severity CVSS v4.0: Pending analysis
Last modification:
12/10/2022

CVE-2022-41523

Publication date:
06/10/2022
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the command parameter in the setTracerouteCfg function.
Severity CVSS v4.0: Pending analysis
Last modification:
12/10/2022

CVE-2022-41524

Publication date:
06/10/2022
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the week, sTime, and eTime parameters in the setParentalRules function.
Severity CVSS v4.0: Pending analysis
Last modification:
12/10/2022

CVE-2022-42457

Publication date:
06/10/2022
Generex CS141 through 2.10 allows remote command execution by administrators via a web interface that reaches run_update in /usr/bin/gxserve-update.sh (e.g., command execution can occur via a reverse shell installed by install.sh).
Severity CVSS v4.0: Pending analysis
Last modification:
10/11/2022

CVE-2022-42243

Publication date:
06/10/2022
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/manage_storage.php?id=.
Severity CVSS v4.0: Pending analysis
Last modification:
28/12/2023

CVE-2022-42249

Publication date:
06/10/2022
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/view_storage.php?id=.
Severity CVSS v4.0: Pending analysis
Last modification:
15/10/2024

CVE-2022-42250

Publication date:
06/10/2022
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/inquiries/view_details.php?id=.
Severity CVSS v4.0: Pending analysis
Last modification:
28/12/2023

CVE-2022-42242

Publication date:
06/10/2022
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/classes/Master.php?f=delete_booking.
Severity CVSS v4.0: Pending analysis
Last modification:
28/12/2023

CVE-2022-42241

Publication date:
06/10/2022
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/classes/Master.php?f=delete_message.
Severity CVSS v4.0: Pending analysis
Last modification:
28/12/2023