Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-14867

Publication date:
28/06/2019
Incorrect access control in the portal messaging system in Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 allows remote attackers to post messages on behalf of customers, and to guess document attribute values, via crafted parameters.
Severity CVSS v4.0: Pending analysis
Last modification:
05/07/2019

CVE-2018-14885

Publication date:
28/06/2019
Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote attacker to restore a database dump without knowing the super-admin password. An arbitrary password succeeds.
Severity CVSS v4.0: Pending analysis
Last modification:
05/07/2019

CVE-2018-14887

Publication date:
28/06/2019
Improper Host header sanitization in the dbfilter routing component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows a remote attacker to deny access to the service and to disclose database names via a crafted request.
Severity CVSS v4.0: Pending analysis
Last modification:
05/07/2019

CVE-2018-17170

Publication date:
28/06/2019
Grouptime Teamwire Desktop Client 1.5.1 prior to 1.9.0 on Windows allows code injection via a template, leading to remote code execution. All backend versions prior to prod-2018-11-13-15-00-42 are affected.
Severity CVSS v4.0: Pending analysis
Last modification:
05/07/2019

CVE-2018-17560

Publication date:
28/06/2019
The admin interface of the Grouptime Teamwire Client 1.5.1 prior to 1.9.0 on-premises messenger server allows stored XSS. All backend versions prior to prod-2018-11-13-15-00-42 are affected.
Severity CVSS v4.0: Pending analysis
Last modification:
05/07/2019

CVE-2018-20807

Publication date:
28/06/2019
An XSS issue has been found in welcome.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1.x before 8.1R12, 8.2.x before 8.2R9, and 8.3.x before 8.3R3 due to one of the URL parameters not being sanitized properly.
Severity CVSS v4.0: Pending analysis
Last modification:
27/02/2024

CVE-2018-14918

Publication date:
28/06/2019
LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal.
Severity CVSS v4.0: Pending analysis
Last modification:
03/07/2019

CVE-2018-20808

Publication date:
28/06/2019
An XSS issue has been found with rd.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R3 due to improper header sanitization. This is not applicable to 8.1RX.
Severity CVSS v4.0: Pending analysis
Last modification:
27/02/2024

CVE-2018-14868

Publication date:
28/06/2019
Incorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to change the password of other users without knowing their current password via a crafted RPC call.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2018-14886

Publication date:
28/06/2019
The module-description renderer in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier does not disable RST's local file inclusion, which allows privileged authenticated users to read local files via a crafted module description.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2018-14916

Publication date:
28/06/2019
LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2018-15519

Publication date:
28/06/2019
Various Lexmark devices have a Buffer Overflow (issue 1 of 2).
Severity CVSS v4.0: Pending analysis
Last modification:
05/07/2019