Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-2229

Publication date:
12/08/2020
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
02/11/2023

CVE-2020-2230

Publication date:
12/08/2020
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.
Severity CVSS v4.0: Pending analysis
Last modification:
02/11/2023

CVE-2020-2231

Publication date:
12/08/2020
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.
Severity CVSS v4.0: Pending analysis
Last modification:
02/11/2023

CVE-2020-17496

Publication date:
12/08/2020
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759.
Severity CVSS v4.0: Pending analysis
Last modification:
14/03/2025

CVE-2020-13278

Publication date:
12/08/2020
Reflected Cross-Site Scripting vulnerability in Modules.php in RosarioSIS Student Information System
Severity CVSS v4.0: Pending analysis
Last modification:
17/08/2020

CVE-2020-16266

Publication date:
12/08/2020
An XSS issue was discovered in MantisBT before 2.24.2. Improper escaping on view_all_bug_page.php allows a remote attacker to inject arbitrary HTML into the page by saving it into a text Custom Field, leading to possible code execution in the browser of any user subsequently viewing the issue (if CSP settings allow it).
Severity CVSS v4.0: Pending analysis
Last modification:
17/08/2020

CVE-2020-17372

Publication date:
12/08/2020
SugarCRM before 10.1.0 (Q3 2020) allows XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
13/08/2020

CVE-2020-16145

Publication date:
12/08/2020
Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-17373

Publication date:
12/08/2020
SugarCRM before 10.1.0 (Q3 2020) allows SQL Injection.
Severity CVSS v4.0: Pending analysis
Last modification:
16/11/2022

CVE-2020-6932

Publication date:
12/08/2020
An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versions 6.4.0 to 6.6.0 could allow an attacker to potentially read arbitrary files and run arbitrary executables in the context of the web server.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-8913

Publication date:
12/08/2020
A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Library versions prior to 1.7.2. A malicious attacker could create an apk which targets a specific application, and if a victim were to install this apk, the attacker could perform a directory traversal, execute code as the targeted application and access the targeted application's data on the Android device. We recommend all users update Play Core to version 1.7.2 or later.
Severity CVSS v4.0: Pending analysis
Last modification:
07/10/2022

CVE-2020-7029

Publication date:
11/08/2020
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager and Avaya Aura Messaging. This vulnerability could allow an unauthenticated remote attacker to perform Web administration actions with the privileged level of the authenticated user. Affected versions of Communication Manager are 7.0.x, 7.1.x prior to 7.1.3.5 and 8.0.x. Affected versions of Messaging are 7.0.x, 7.1 and 7.1 SP1.
Severity CVSS v4.0: Pending analysis
Last modification:
17/08/2020