Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-29001

Publication date:
03/05/2022
In SpringBootMovie
Severity CVSS v4.0: Pending analysis
Last modification:
10/05/2022

CVE-2022-28599

Publication date:
03/05/2022
A stored cross-site scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 that allows an authenticated user to upload a malicious .pdf file which acts as a stored XSS payload. If this stored XSS payload is triggered by an administrator it will trigger a XSS attack.
Severity CVSS v4.0: Pending analysis
Last modification:
10/05/2022

CVE-2022-28588

Publication date:
03/05/2022
In SpringBootMovie
Severity CVSS v4.0: Pending analysis
Last modification:
10/05/2022

CVE-2022-28585

Publication date:
03/05/2022
EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php
Severity CVSS v4.0: Pending analysis
Last modification:
09/05/2022

CVE-2021-46440

Publication date:
03/05/2022
Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to access a victim's HTTP request, get the victim's cookie, perform a base64 decode on the victim's cookie, and obtain a cleartext password, leading to getting API documentation for further API attacks.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2022

CVE-2022-28505

Publication date:
03/05/2022
Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java.
Severity CVSS v4.0: Pending analysis
Last modification:
10/05/2022

CVE-2022-27962

Publication date:
03/05/2022
Bluecms 1.6 has a SQL injection vulnerability at cooike.
Severity CVSS v4.0: Pending analysis
Last modification:
09/05/2022

CVE-2022-22137

Publication date:
03/05/2022
A memory corruption vulnerability exists in the ioca_mys_rgb_allocate functionality of Accusoft ImageGear 19.10. A specially-crafted malformed file can lead to an arbitrary free. An attacker can provide a malicious file to trigger this vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
10/05/2022

CVE-2022-28561

Publication date:
03/05/2022
There is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda ax12 22.03.01.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload
Severity CVSS v4.0: Pending analysis
Last modification:
09/05/2022

CVE-2022-23400

Publication date:
03/05/2022
A stack-based buffer overflow vulnerability exists in the IGXMPXMLParser::parseDelimiter functionality of Accusoft ImageGear 19.10. A specially-crafted PSD file can overflow a stack buffer, which could either lead to denial of service or, depending on the application, to an information leak. An attacker can provide a malicious file to trigger this vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
10/05/2022

CVE-2022-28560

Publication date:
03/05/2022
There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 15.03.2.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload
Severity CVSS v4.0: Pending analysis
Last modification:
11/05/2022

CVE-2021-22573

Publication date:
03/05/2022
The vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sure that the token's payload comes from valid provider, not from someone else. An attacker can provide a compromised token with custom payload. The token will pass the validation on the client side. We recommend upgrading to version 1.33.3 or above
Severity CVSS v4.0: Pending analysis
Last modification:
10/05/2022