Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-33891

Publication date:
18/07/2022
The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. A malicious user might then be able to reach a permission check function that will ultimately build a Unix shell command based on their input, and execute it. This will result in arbitrary shell command execution as the user Spark is currently running as. This affects Apache Spark versions 3.0.3 and earlier, versions 3.1.1 to 3.1.2, and versions 3.2.0 to 3.2.1.
Severity CVSS v4.0: Pending analysis
Last modification:
23/10/2025

CVE-2022-27434

Publication date:
18/07/2022
UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileName parameter in the errorReporting page.
Severity CVSS v4.0: Pending analysis
Last modification:
25/07/2022

CVE-2021-44954

Publication date:
18/07/2022
In QVIS NVR DVR before 2021-12-13, an attacker can escalate privileges from a qvisdvr user to the root user by abusing a Sudo misconfiguration.
Severity CVSS v4.0: Pending analysis
Last modification:
25/07/2022

CVE-2021-42923

Publication date:
18/07/2022
ShowMyPC 3606 on Windows suffers from a DLL hijack vulnerability. If an attacker overwrites the file %temp%\ShowMyPC\-ShowMyPC3606\wodVPN.dll, it will run any malicious code contained in that file. The code will run with normal user privileges unless the user specifically runs ShowMyPC as administrator.
Severity CVSS v4.0: Pending analysis
Last modification:
25/07/2022

CVE-2021-41419

Publication date:
18/07/2022
QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.
Severity CVSS v4.0: Pending analysis
Last modification:
25/07/2022

CVE-2021-40874

Publication date:
18/07/2022
An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with the Combination authentication plug-in, any password will be recognized as valid for an existing user.
Severity CVSS v4.0: Pending analysis
Last modification:
25/07/2022

CVE-2020-23562

Publication date:
18/07/2022
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000000aefe.
Severity CVSS v4.0: Pending analysis
Last modification:
25/07/2022

CVE-2020-23561

Publication date:
18/07/2022
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000005722.
Severity CVSS v4.0: Pending analysis
Last modification:
25/07/2022

CVE-2020-16093

Publication date:
18/07/2022
In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.
Severity CVSS v4.0: Pending analysis
Last modification:
28/02/2023

CVE-2020-23563

Publication date:
18/07/2022
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000002cba.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2022

CVE-2022-33903

Publication date:
17/07/2022
Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.
Severity CVSS v4.0: Pending analysis
Last modification:
03/05/2023

CVE-2022-31213

Publication date:
17/07/2022
An issue was discovered in dbus-broker before 31. Multiple NULL pointer dereferences can be found when supplying a malformed XML config file.
Severity CVSS v4.0: Pending analysis
Last modification:
03/05/2023