Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-0408

Publication date:
30/01/2022
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2022-0413

Publication date:
30/01/2022
Use After Free in GitHub repository vim/vim prior to 8.2.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2022-0273

Publication date:
30/01/2022
Improper Access Control in Pypi calibreweb prior to 0.6.16.
Severity CVSS v4.0: Pending analysis
Last modification:
19/11/2024

CVE-2022-0339

Publication date:
30/01/2022
Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16.
Severity CVSS v4.0: Pending analysis
Last modification:
19/11/2024

CVE-2022-0407

Publication date:
30/01/2022
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2022

CVE-2022-22919

Publication date:
30/01/2022
Adenza AxiomSL ControllerView through 10.8.1 allows redirection for SSO login URLs.
Severity CVSS v4.0: Pending analysis
Last modification:
04/02/2022

CVE-2022-24032

Publication date:
30/01/2022
Adenza AxiomSL ControllerView through 10.8.1 is vulnerable to user enumeration. An attacker can identify valid usernames on the platform because a failed login attempt produces a different error message when the username is valid.
Severity CVSS v4.0: Pending analysis
Last modification:
08/08/2023

CVE-2021-46660

Publication date:
30/01/2022
Signiant Manager+Agents before 15.1 allows XML External Entity (XXE) attacks.
Severity CVSS v4.0: Pending analysis
Last modification:
04/02/2022

CVE-2022-24123

Publication date:
29/01/2022
MarkText through 0.16.3 does not sanitize the input of a mermaid block before rendering. This could lead to Remote Code Execution via a .md file containing a mutation Cross-Site Scripting (XSS) payload.
Severity CVSS v4.0: Pending analysis
Last modification:
04/02/2022

CVE-2022-24124

Publication date:
29/01/2022
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.
Severity CVSS v4.0: Pending analysis
Last modification:
05/04/2022

CVE-2021-46659

Publication date:
29/01/2022
MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2021-46657

Publication date:
29/01/2022
get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2022