Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-1511

Publication date:
28/04/2022
Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4.
Severity CVSS v4.0: Pending analysis
Last modification:
15/02/2024

CVE-2022-22782

Publication date:
28/04/2022
The Zoom Client for Meetings for Windows prior to version 5.9.7, Zoom Rooms for Conference Room for Windows prior to version 5.10.0, Zoom Plugins for Microsoft Outlook for Windows prior to version 5.10.3, and Zoom VDI Windows Meeting Clients prior to version 5.9.6; was susceptible to a local privilege escalation issue during the installer repair operation. A malicious actor could utilize this to potentially delete system level files or folders, causing integrity or availability issues on the user’s host machine.
Severity CVSS v4.0: Pending analysis
Last modification:
08/08/2023

CVE-2022-22783

Publication date:
28/04/2022
A vulnerability in Zoom On-Premise Meeting Connector Controller version 4.8.102.20220310 and On-Premise Meeting Connector MMR version 4.8.102.20220310 exposes process memory fragments to connected clients, which could be observed by a passive attacker.
Severity CVSS v4.0: Pending analysis
Last modification:
08/08/2023

CVE-2021-43930

Publication date:
28/04/2022
Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabling malicious users to perform path traversal attacks and potentially download arbitrary files from the system.
Severity CVSS v4.0: Pending analysis
Last modification:
09/05/2022

CVE-2022-24873

Publication date:
28/04/2022
Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cross-site scripting in the storefront. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the Shopware security plugin.
Severity CVSS v4.0: Pending analysis
Last modification:
06/05/2022

CVE-2022-28102

Publication date:
28/04/2022
A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected at /edit-db.php.
Severity CVSS v4.0: Pending analysis
Last modification:
14/02/2024

CVE-2022-28101

Publication date:
28/04/2022
Turtlapp Turtle Note v0.7.2.6 does not filter the tag during markdown parsing, allowing attackers to execute HTML injection.
Severity CVSS v4.0: Pending analysis
Last modification:
06/05/2022

CVE-2021-41945

Publication date:
28/04/2022
Encode OSS httpx
Severity CVSS v4.0: Pending analysis
Last modification:
12/10/2022

CVE-2022-29152

Publication date:
28/04/2022
The Ericom PowerTerm WebConnect 6.0 login portal can unsafely write an XSS payload from the AppPortal cookie into the page.
Severity CVSS v4.0: Pending analysis
Last modification:
06/05/2022

CVE-2021-41921

Publication date:
28/04/2022
novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
13/09/2023

CVE-2022-24935

Publication date:
28/04/2022
Lexmark products through 2022-02-10 have Incorrect Access Control.
Severity CVSS v4.0: Pending analysis
Last modification:
08/08/2023

CVE-2021-33436

Publication date:
28/04/2022
NoMachine for Windows prior to version 6.15.1 and 7.5.2 suffer from local privilege escalation due to the lack of safe DLL loading. This vulnerability allows local non-privileged users to perform DLL Hijacking via any writable directory listed under the system path and ultimately execute code as NT AUTHORITY\SYSTEM.
Severity CVSS v4.0: Pending analysis
Last modification:
07/05/2022