Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-27560

Publication date:
22/10/2020
ImageMagick 7.0.10-34 allows Division by Zero in OptimizeLayerFrames in MagickCore/layer.c, which may cause a denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
11/03/2023

CVE-2020-27642

Publication date:
22/10/2020
A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.
Severity CVSS v4.0: Pending analysis
Last modification:
27/10/2020

CVE-2020-27638

Publication date:
22/10/2020
receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-27621

Publication date:
22/10/2020
The FileImporter extension in MediaWiki through 1.35.0 was not properly attributing various user actions to a specific user's IP address. Instead, for various actions, it would report the IP address of an internal Wikimedia Foundation server by omitting X-Forwarded-For data. This resulted in an inability to properly audit and attribute various user actions performed via the FileImporter extension.
Severity CVSS v4.0: Pending analysis
Last modification:
02/11/2020

CVE-2020-27620

Publication date:
22/10/2020
The Cosmos Skin for MediaWiki through 1.35.0 has stored XSS because MediaWiki messages were not being properly escaped. This is related to wfMessage and Html::rawElement, as demonstrated by CosmosSocialProfile::getUserGroups.
Severity CVSS v4.0: Pending analysis
Last modification:
26/10/2020

CVE-2020-27619

Publication date:
22/10/2020
In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.
Severity CVSS v4.0: Pending analysis
Last modification:
03/02/2024

CVE-2020-17454

Publication date:
21/10/2020
WSO2 API Manager 3.1.0 and earlier has reflected XSS on the "publisher" component's admin interface. More precisely, it is possible to inject an XSS payload into the owner POST parameter, which does not filter user inputs. By putting an XSS payload in place of a valid Owner Name, a modal box appears that writes an error message concatenated to the injected payload (without any form of data encoding). This can also be exploited via CSRF.
Severity CVSS v4.0: Pending analysis
Last modification:
26/10/2020

CVE-2020-24421

Publication date:
21/10/2020
Adobe InDesign version 15.1.2 (and earlier) is affected by a NULL pointer dereference bug that occurs when handling a malformed .indd file. The impact is limited to causing a denial-of-service of the client application. User interaction is required to exploit this issue.
Severity CVSS v4.0: Pending analysis
Last modification:
10/12/2021

CVE-2020-17355

Publication date:
21/10/2020
Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (restart of agents) by crafting a malformed DHCP packet which leads to an incorrect route being installed.
Severity CVSS v4.0: Pending analysis
Last modification:
02/11/2020

CVE-2020-27615

Publication date:
21/10/2020
The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip.
Severity CVSS v4.0: Pending analysis
Last modification:
23/10/2020

CVE-2020-24425

Publication date:
21/10/2020
Dreamweaver version 20.2 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. Successful exploitation could result in a local user with permissions to write to the file system running system commands with administrator privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2021

CVE-2020-24420

Publication date:
21/10/2020
Adobe Photoshop for Windows version 21.2.1 (and earlier) is affected by an uncontrolled search path element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Severity CVSS v4.0: Pending analysis
Last modification:
29/10/2020