Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-0015

Publication date:
12/01/2022
A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute programs with elevated privileges. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12; Cortex XDR agent 6.1 versions earlier than Cortex XDR agent 6.1.9.
Severity CVSS v4.0: Pending analysis
Last modification:
19/01/2022

CVE-2021-28376

Publication date:
12/01/2022
ChronoForms 7.0.7 allows fname Directory Traversal to read arbitrary files.
Severity CVSS v4.0: Pending analysis
Last modification:
18/01/2022

CVE-2021-28377

Publication date:
12/01/2022
ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files.
Severity CVSS v4.0: Pending analysis
Last modification:
18/01/2022

CVE-2021-45445

Publication date:
12/01/2022
Unisys ClearPath MCP TCP/IP Networking Services 59.1, 60.0, and 62.0 has an Infinite Loop.
Severity CVSS v4.0: Pending analysis
Last modification:
19/01/2022

CVE-2021-45411

Publication date:
12/01/2022
In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
20/01/2022

CVE-2021-43436

Publication date:
12/01/2022
MartDevelopers Inc iResturant v1.0 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2021-45388

Publication date:
12/01/2022
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-45608. Reason: This candidate is a reservation duplicate of CVE-2021-45608. Notes: All CVE users should reference CVE-2021-45608 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2021-38892

Publication date:
12/01/2022
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2021-44652

Publication date:
12/01/2022
Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component.
Severity CVSS v4.0: Pending analysis
Last modification:
25/01/2022

CVE-2021-44651

Publication date:
12/01/2022
Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175.
Severity CVSS v4.0: Pending analysis
Last modification:
24/01/2022

CVE-2021-4080

Publication date:
12/01/2022
crater is vulnerable to Unrestricted Upload of File with Dangerous Type
Severity CVSS v4.0: Pending analysis
Last modification:
18/01/2022

CVE-2021-44650

Publication date:
12/01/2022
Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components.
Severity CVSS v4.0: Pending analysis
Last modification:
24/01/2022