Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-29821

Publication date:
28/04/2022
In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2022

CVE-2022-29818

Publication date:
28/04/2022
In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2022

CVE-2022-29819

Publication date:
28/04/2022
In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2022

CVE-2022-29820

Publication date:
28/04/2022
In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2022

CVE-2022-29817

Publication date:
28/04/2022
In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2022

CVE-2022-29814

Publication date:
28/04/2022
In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2022

CVE-2022-29815

Publication date:
28/04/2022
In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2022

CVE-2022-29812

Publication date:
28/04/2022
In JetBrains IntelliJ IDEA before 2022.1 notification mechanisms about using Unicode directionality formatting characters were insufficient
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2022

CVE-2022-29813

Publication date:
28/04/2022
In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2022

CVE-2022-29816

Publication date:
28/04/2022
In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible
Severity CVSS v4.0: Pending analysis
Last modification:
28/06/2023

CVE-2022-1509

Publication date:
28/04/2022
Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.
Severity CVSS v4.0: Pending analysis
Last modification:
30/08/2024

CVE-2022-29811

Publication date:
28/04/2022
In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible.
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2022