Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-6177

Publication date:
12/02/2020
SAP Mobile Platform, version 3.0, does not sufficiently validate an XML document accepted from an untrusted source which could lead to partial denial of service. Since SAP Mobile Platform does not allow External-Entity resolving, there is no issue of leaking content of files on the server.
Severity CVSS v4.0: Pending analysis
Last modification:
19/02/2020

CVE-2020-6184

Publication date:
12/02/2020
Under certain conditions, ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), does not sufficiently encode user-controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
19/02/2020

CVE-2020-6183

Publication date:
12/02/2020
SAP Host Agent, version 7.21, allows an unprivileged user to read the shared memory or write to the shared memory by sending request to the main SAPOSCOL process and receive responses that may contain data read with user root privileges e.g. size of any directory, system hardware and OS details, leading to Missing Authorization Check vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
20/02/2020

CVE-2011-3901

Publication date:
12/02/2020
Android SQLite Journal before 4.0.1 has an information disclosure vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2011-2499

Publication date:
12/02/2020
Mambo CMS through 4.6.5 has multiple XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2011-3336

Publication date:
12/02/2020
regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2020-8949

Publication date:
12/02/2020
Gocloud S2A_WL 4.2.7.16471, S2A 4.2.7.17278, S2A 4.3.0.15815, S2A 4.3.0.17193, S3A K2P MTK 4.2.7.16528, S3A 4.3.0.16572, and ISP3000 4.3.0.17190 devices allows remote attackers to execute arbitrary OS commands via shell metacharacters in a ping operation, as demonstrated by the cgi-bin/webui/admin/tools/app_ping/diag_ping/; substring.
Severity CVSS v4.0: Pending analysis
Last modification:
25/02/2020

CVE-2019-17519

Publication date:
12/02/2020
The Bluetooth Low Energy implementation on NXP SDK through 2.2.1 for KW41Z devices does not properly restrict the Link Layer payload length, allowing attackers in radio range to cause a buffer overflow via a crafted packet.
Severity CVSS v4.0: Pending analysis
Last modification:
02/11/2022

CVE-2019-19192

Publication date:
12/02/2020
The Bluetooth Low Energy implementation on STMicroelectronics BLE Stack through 1.3.1 for STM32WB5x devices does not properly handle consecutive Attribute Protocol (ATT) requests on reception, allowing attackers in radio range to cause an event deadlock or crash via crafted packets.
Severity CVSS v4.0: Pending analysis
Last modification:
26/02/2020

CVE-2011-4338

Publication date:
12/02/2020
Shaman 1.0.9: Users can add the line askforpwd=false to his shaman.conf file, without entering the root password in shaman. The next time shaman is run, root privileges are granted despite the fact that the user never entered the root password.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2013-3725

Publication date:
12/02/2020
Invision Power Board (IPB) through 3.x allows admin account takeover leading to code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
25/02/2020

CVE-2014-3860

Publication date:
12/02/2020
Xilisoft Video Converter Ultimate 7.8.1 build-20140505 has a DLL Hijacking vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
19/02/2020