Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-33616

Publication date:
04/04/2022
RSA Archer 6.x through 6.9 SP1 P4 (6.9.1.4) allows stored XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2022

CVE-2022-1224

Publication date:
04/04/2022
Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2022

CVE-2022-1225

Publication date:
04/04/2022
Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2022

CVE-2022-24191

Publication date:
04/04/2022
In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2022-1223

Publication date:
04/04/2022
Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
Severity CVSS v4.0: Pending analysis
Last modification:
24/02/2026

CVE-2022-0939

Publication date:
04/04/2022
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
Severity CVSS v4.0: Pending analysis
Last modification:
19/11/2024

CVE-2022-1222

Publication date:
04/04/2022
Inf loop in GitHub repository gpac/gpac prior to 2.1.0-DEV.
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2023

CVE-2022-27249

Publication date:
03/04/2022
An unrestricted file upload vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to execute arbitrary code by using UploadDwg to upload a crafted aspx file to the web root, and then visiting the URL for this aspx resource.
Severity CVSS v4.0: Pending analysis
Last modification:
09/04/2022

CVE-2022-27248

Publication date:
03/04/2022
A directory traversal vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to download arbitrary .dwg files from a remote server by specifying an absolute or relative path when invoking the affected DownloadDwg endpoint. An attack uses the path field to CaddemServiceJS/CaddemService.svc/rest/DownloadDwg.
Severity CVSS v4.0: Pending analysis
Last modification:
09/04/2022

CVE-2022-26233

Publication date:
03/04/2022
Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensitive information and components. Requests must begin with the "GET /..\.." substring.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2022

CVE-2022-26530

Publication date:
03/04/2022
swaylock before 1.6 allows attackers to trigger a crash and achieve unlocked access to a Wayland compositor.
Severity CVSS v4.0: Pending analysis
Last modification:
19/04/2022

CVE-2021-30066

Publication date:
03/04/2022
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitrary firmware image can be loaded because firmware signature verification (for a USB stick) can be bypassed. NOTE: this issue exists because of an incomplete fix of CVE-2017-11400.
Severity CVSS v4.0: Pending analysis
Last modification:
09/04/2022