Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-19945

Publication date:
31/12/2020
A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitations of a pathname to a restricted directory, this vulnerability allows for renaming arbitrary files on the target system, if exploited. QNAP have already fixed this vulnerability in the following versions: QTS 4.3.6.0895 build 20190328 (and later) QTS 4.3.4.0899 build 20190322 (and later) This issue does not affect QTS 4.4.x or QTS 4.5.x.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2021

CVE-2018-19944

Publication date:
31/12/2020
A cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices. If exploited, this vulnerability allows a remote attacker to gain access to sensitive information. QNAP have already fixed this vulnerability in the following versions: QTS 4.4.3.1354 build 20200702 (and later)
Severity CVSS v4.0: Pending analysis
Last modification:
07/01/2021

CVE-2018-19941

Publication date:
31/12/2020
A vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows an attacker to access sensitive information stored in cleartext inside cookies via certain widely-available tools. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and later) QuTS hero h4.5.1.1472 build 20201031 (and later) QuTScloud c4.5.2.1379 build 20200730 (and later)
Severity CVSS v4.0: Pending analysis
Last modification:
07/01/2021

CVE-2020-35897

Publication date:
31/12/2020
An issue was discovered in the atom crate before 0.3.6 for Rust. An unsafe Send implementation allows a cross-thread data race.
Severity CVSS v4.0: Pending analysis
Last modification:
07/01/2021

CVE-2020-35895

Publication date:
31/12/2020
An issue was discovered in the stack crate before 0.3.1 for Rust. ArrayVec has an out-of-bounds write via element insertion.
Severity CVSS v4.0: Pending analysis
Last modification:
14/12/2022

CVE-2020-35896

Publication date:
31/12/2020
An issue was discovered in the ws crate through 2020-09-25 for Rust. The outgoing buffer is not properly limited, leading to a remote memory-consumption attack.
Severity CVSS v4.0: Pending analysis
Last modification:
03/12/2022

CVE-2020-35884

Publication date:
31/12/2020
An issue was discovered in the tiny_http crate through 2020-06-16 for Rust. HTTP Request smuggling can occur via a malformed Transfer-Encoding header.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-35887

Publication date:
31/12/2020
An issue was discovered in the arr crate through 2020-08-25 for Rust. There is a buffer overflow in Index and IndexMut.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2021

CVE-2020-35892

Publication date:
31/12/2020
An issue was discovered in the simple-slab crate before 0.3.3 for Rust. index() allows an out-of-bounds read.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2021

CVE-2020-35891

Publication date:
31/12/2020
An issue was discovered in the ordnung crate through 2020-09-03 for Rust. compact::Vec violates memory safety via a remove() double free.
Severity CVSS v4.0: Pending analysis
Last modification:
07/01/2021

CVE-2020-35890

Publication date:
31/12/2020
An issue was discovered in the ordnung crate through 2020-09-03 for Rust. compact::Vec violates memory safety via out-of-bounds access for large capacity.
Severity CVSS v4.0: Pending analysis
Last modification:
07/01/2021

CVE-2020-35894

Publication date:
31/12/2020
An issue was discovered in the obstack crate before 0.1.4 for Rust. Unaligned references can occur.
Severity CVSS v4.0: Pending analysis
Last modification:
07/01/2021