Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-0512

Publication date:
14/02/2022
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.
Severity CVSS v4.0: Pending analysis
Last modification:
23/02/2023

CVE-2021-46371

Publication date:
14/02/2022
antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the foreground leads to leakage of sensitive information.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2022

CVE-2022-24686

Publication date:
14/02/2022
HashiCorp Nomad and Nomad Enterprise 0.3.0 through 1.0.17, 1.1.11, and 1.2.5 artifact download functionality has a race condition such that the Nomad client agent could download the wrong artifact into the wrong destination. Fixed in 1.0.18, 1.1.12, and 1.2.6
Severity CVSS v4.0: Pending analysis
Last modification:
11/05/2022

CVE-2021-45420

Publication date:
14/02/2022
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system without any kind of authentication mechanism, and this can lead to denial of service and potentially remote code execution. Note: the product has not been supported since 2018 and should be removed or replaced
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2024

CVE-2021-45421

Publication date:
14/02/2022
Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can use this misconfiguration to access all the files in the remote directories. Note: the product has not been supported since 2018 and should be removed or replaced
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2024

CVE-2022-24976

Publication date:
14/02/2022
Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certain point during a challenge-response login sequence.
Severity CVSS v4.0: Pending analysis
Last modification:
23/02/2022

CVE-2022-24977

Publication date:
14/02/2022
ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe interaction with the CKEditor processImage.php script. The payload may be placed in PHP_SESSION_UPLOAD_PROGRESS when the PHP installation supports upload_progress.
Severity CVSS v4.0: Pending analysis
Last modification:
24/02/2022

CVE-2022-24110

Publication date:
14/02/2022
Kiteworks MFT 7.5 may allow an unauthorized user to reset other users' passwords. This is fixed in version 7.6 and later.
Severity CVSS v4.0: Pending analysis
Last modification:
08/08/2023

CVE-2022-0575

Publication date:
14/02/2022
Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.2.0.
Severity CVSS v4.0: Pending analysis
Last modification:
23/02/2022

CVE-2022-0576

Publication date:
14/02/2022
Cross-site Scripting (XSS) - Generic in Packagist librenms/librenms prior to 22.1.0.
Severity CVSS v4.0: Pending analysis
Last modification:
23/02/2022

CVE-2022-0572

Publication date:
14/02/2022
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2025

CVE-2022-0570

Publication date:
14/02/2022
Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.
Severity CVSS v4.0: Pending analysis
Last modification:
22/02/2022