Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-39868

Publication date:
04/10/2021
In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.
Severity CVSS v4.0: Pending analysis
Last modification:
12/10/2021

CVE-2021-39871

Publication date:
04/10/2021
In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import enabled is bypassed by an attacker making a crafted API call.
Severity CVSS v4.0: Pending analysis
Last modification:
12/10/2021

CVE-2021-39873

Publication date:
04/10/2021
In all versions of GitLab CE/EE, there exists a content spoofing vulnerability which may be leveraged by attackers to trick users into visiting a malicious website by spoofing the content in an error response.
Severity CVSS v4.0: Pending analysis
Last modification:
12/10/2021

CVE-2021-25964

Publication date:
04/10/2021
In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access to edit the metadata information, can inject JavaScript payload in the description field. When a victim tries to open the file, XSS will be triggered.
Severity CVSS v4.0: Pending analysis
Last modification:
19/11/2024

CVE-2021-37777

Publication date:
04/10/2021
Gila CMS 2.2.0 is vulnerable to Insecure Direct Object Reference (IDOR). Thumbnails uploaded by one site owner are visible by another site owner just by knowing the other site name and fuzzing for picture names. This leads to sensitive information disclosure.
Severity CVSS v4.0: Pending analysis
Last modification:
03/05/2022

CVE-2021-38822

Publication date:
04/10/2021
A Stored Cross Site Scripting vulnerability via Malicious File Upload exists in multiple pages of IceHrm 30.0.0.OS that allows for arbitrary execution of JavaScript commands.
Severity CVSS v4.0: Pending analysis
Last modification:
08/10/2021

CVE-2021-39486

Publication date:
04/10/2021
A Stored XSS via Malicious File Upload exists in Gila CMS version 2.2.0. An attacker can use this to steal cookies, passwords or to run arbitrary code on a victim's browser.
Severity CVSS v4.0: Pending analysis
Last modification:
12/10/2021

CVE-2021-41868

Publication date:
04/10/2021
OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to upload files on a non-public node when using the --receive functionality.
Severity CVSS v4.0: Pending analysis
Last modification:
12/10/2021

CVE-2021-41867

Publication date:
04/10/2021
An information disclosure vulnerability in OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to retrieve the full list of participants of a non-public OnionShare node via the --chat feature.
Severity CVSS v4.0: Pending analysis
Last modification:
12/10/2021

CVE-2021-38823

Publication date:
04/10/2021
The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue. A signout from an admin account does not invalidate an admin session that is opened in a different browser.
Severity CVSS v4.0: Pending analysis
Last modification:
12/10/2021

CVE-2021-37330

Publication date:
04/10/2021
Laravel Booking System Booking Core 2.0 is vulnerable to Cross Site Scripting (XSS). The Avatar upload in the My Profile section could be exploited to upload a malicious SVG file which contains Javascript. Now if another user/admin views the profile and clicks to view his avatar, an XSS will trigger.
Severity CVSS v4.0: Pending analysis
Last modification:
12/10/2021

CVE-2021-37333

Publication date:
04/10/2021
Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.org/user/profile/change-password does not invalidate a session that is opened in a different browser.
Severity CVSS v4.0: Pending analysis
Last modification:
12/10/2021