Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-23902

Publication date:
14/02/2022
Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in export_data.php via the d_name parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
16/12/2023

CVE-2021-45310

Publication date:
14/02/2022
Sangoma Technologies Corporation Switchvox Version 102409 is affected by an information disclosure vulnerability due to an improper access restriction. Users information such as first name, last name, acount id, server uuid, email address, profile image, number, timestamps, etc can be extracted by sending an unauthenticated HTTP GET request to the https://Switchvox-IP/main?cmd=invalid_browser.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2022

CVE-2022-23389

Publication date:
14/02/2022
PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
08/08/2023

CVE-2021-43106

Publication date:
14/02/2022
A Header Injection vulnerability exists in Compass Plus TranzWare Online FIMI Web Interface Tranzware Online (TWO) 5.3.33.3 F38 and FIMI 4.2.19.4 25.The HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header would just cause the request to be sent to a completely different Domain/IP address. This is due to that the server implicitly trusts the Host header, and fails to validate or escape it properly. An attacker can use this input to redirect target users to a malicious domain/web page. This would result in expanding the potential to further attacks and malicious actions.
Severity CVSS v4.0: Pending analysis
Last modification:
23/02/2022

CVE-2019-16864

Publication date:
14/02/2022
CompleteFTPService.exe in the server in EnterpriseDT CompleteFTP before 12.1.4 allows Remote Code Execution by leveraging a Windows user account that has SSH access. The exec command is always run as SYSTEM.
Severity CVSS v4.0: Pending analysis
Last modification:
23/02/2022

CVE-2021-45348

Publication date:
14/02/2022
An Arbitrary File Deletion vulnerability exists in SourceCodester Attendance Management System v1.0 via the csv parameter in admin/pageUploadCSV.php, which can cause a Denial of Service (crash).
Severity CVSS v4.0: Pending analysis
Last modification:
23/02/2022

CVE-2022-24988

Publication date:
14/02/2022
In galois_2p8 before 0.1.2, PrimitivePolynomialField::new has an off-by-one buffer overflow for a vector.
Severity CVSS v4.0: Pending analysis
Last modification:
08/08/2023

CVE-2022-25150

Publication date:
14/02/2022
In Malwarebytes Binisoft Windows Firewall Control before 6.8.1.0, programs executed from the Tools tab can be used to escalate privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
23/02/2022

CVE-2021-45347

Publication date:
14/02/2022
An Incorrect Access Control vulnerability exists in zzcms 8.2, which lets a malicious user bypass authentication by changing the user name in the cookie to use any password.
Severity CVSS v4.0: Pending analysis
Last modification:
23/02/2022

CVE-2021-45346

Publication date:
14/02/2022
A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of memory that extend beyond the record, which could let a malicious user obtain sensitive information. NOTE: The developer disputes this as a vulnerability stating that If you give SQLite a corrupted database file and submit a query against the database, it might read parts of the database that you did not intend or expect.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2024

CVE-2022-0579

Publication date:
14/02/2022
Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9.
Severity CVSS v4.0: Pending analysis
Last modification:
24/02/2026

CVE-2022-23367

Publication date:
14/02/2022
Fulusso v1.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in /BindAccount/SuccessTips.js. This vulnerability allows attackers to inject malicious code into a victim user's device via open redirection.
Severity CVSS v4.0: Pending analysis
Last modification:
23/02/2022