Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-15610

Publication date:
04/02/2020
Improper authorization in the Circles app 0.17.7 causes retaining access when an email address was removed from a circle.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2020

CVE-2019-15613

Publication date:
04/02/2020
A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes.
Severity CVSS v4.0: Pending analysis
Last modification:
11/05/2023

CVE-2019-15612

Publication date:
04/02/2020
A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.
Severity CVSS v4.0: Pending analysis
Last modification:
24/03/2020

CVE-2015-3613

Publication date:
04/02/2020
A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page
Severity CVSS v4.0: Pending analysis
Last modification:
05/02/2020

CVE-2015-3612

Publication date:
04/02/2020
A Cross-site Scripting (XSS) vulnerability exists in FortiManager 5.2.1 and earlier and 5.0.10 and earlier via an unspecified parameter in the FortiWeb auto update service page.
Severity CVSS v4.0: Pending analysis
Last modification:
05/02/2020

CVE-2015-3611

Publication date:
04/02/2020
A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspecified vectors, which could let a malicious user run systems commands when executing a report.
Severity CVSS v4.0: Pending analysis
Last modification:
05/02/2020

CVE-2019-10784

Publication date:
04/02/2020
phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, "database.php" does not verify the source of an HTTP request. This can be leveraged by a remote attacker to trick a logged-in administrator to visit a malicious page with a CSRF exploit and execute arbitrary system commands on the server.
Severity CVSS v4.0: Pending analysis
Last modification:
12/02/2020

CVE-2019-4675

Publication date:
04/02/2020
IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 171511.
Severity CVSS v4.0: Pending analysis
Last modification:
12/02/2020

CVE-2020-4163

Publication date:
04/02/2020
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, under specialized conditions, could allow an authenticated user to create a maliciously crafted file name which would be misinterpreted as jsp content and executed. IBM X-Force ID: 174397.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-7221

Publication date:
04/02/2020
mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2019-4541

Publication date:
04/02/2020
IBM Security Directory Server 6.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 165814.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2019-4562

Publication date:
04/02/2020
IBM Security Directory Server 6.4.0 stores sensitive information in URLs. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history. IBM X-Force ID: 166623.
Severity CVSS v4.0: Pending analysis
Last modification:
04/02/2020