Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-11005

Publication date:
11/01/2021
A Memory Leak issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
Severity CVSS v4.0: Pending analysis
Last modification:
12/01/2021

CVE-2018-11007

Publication date:
11/01/2021
A Memory Leak issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
Severity CVSS v4.0: Pending analysis
Last modification:
12/01/2021

CVE-2018-11010

Publication date:
11/01/2021
A Buffer Overflow issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
Severity CVSS v4.0: Pending analysis
Last modification:
12/01/2021

CVE-2018-11006

Publication date:
11/01/2021
An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
Severity CVSS v4.0: Pending analysis
Last modification:
12/01/2021

CVE-2018-11008

Publication date:
11/01/2021
An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
Severity CVSS v4.0: Pending analysis
Last modification:
12/01/2021

CVE-2018-11009

Publication date:
11/01/2021
A Buffer Overflow issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
Severity CVSS v4.0: Pending analysis
Last modification:
13/01/2021

CVE-2020-2508

Publication date:
11/01/2021
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and later) QuTS hero h4.5.1.1472 build 20201031 (and later)
Severity CVSS v4.0: Pending analysis
Last modification:
14/01/2021

CVE-2020-35483

Publication date:
11/01/2021
AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the application directory, allows this attacker to compromise a local user account via a read-only setting for a Trojan horse gcapi.dll file.
Severity CVSS v4.0: Pending analysis
Last modification:
20/01/2021

CVE-2020-23630

Publication date:
11/01/2021
A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).
Severity CVSS v4.0: Pending analysis
Last modification:
14/01/2021

CVE-2020-26118

Publication date:
11/01/2021
In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialization vulnerability. The application's UpdateMemento class accepts a serialized Java object directly from the user without properly sanitizing it. A malicious object can be submitted to the server via an authenticated attacker to execute commands on the underlying system.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-23849

Publication date:
11/01/2021
Stored XSS was discovered in the tree mode of jsoneditor before 9.0.2 through injecting and executing JavaScript.
Severity CVSS v4.0: Pending analysis
Last modification:
13/01/2021

CVE-2020-23643

Publication date:
11/01/2021
XSS exists in JIZHICMS 1.7.1 via index.php/Wechat/checkWeixin?signature=1&echostr={XSS] to Home/c/WechatController.php.
Severity CVSS v4.0: Pending analysis
Last modification:
13/01/2021