Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-25033

Publication date:
31/08/2020
The Blubrry subscribe-sidebar (aka Subscribe Sidebar) plugin 1.3.1 for WordPress allows subscribe_sidebar.php&status= reflected XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
14/02/2024

CVE-2020-25032

Publication date:
31/08/2020
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
Severity CVSS v4.0: Pending analysis
Last modification:
28/04/2022

CVE-2020-25031

Publication date:
31/08/2020
checkinstall 1.6.2, when used to create a package that contains a symlink, may trigger the creation of a mode 0777 executable file.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2020

CVE-2020-24104

Publication date:
30/08/2020
XSS on the PIX-Link Repeater/Router LV-WR07 with firmware v28K.Router.20170904 allows attackers to steal credentials without being connected to the network. The attack vector is a crafted ESSID, as demonstrated by the wireless.htm SET2 parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
31/08/2020

CVE-2020-8097

Publication date:
30/08/2020
An improper authentication vulnerability in Bitdefender Endpoint Security Tools for Windows and Bitdefender Endpoint Security SDK allows an unprivileged local attacker to escalate privileges or tamper with the product's security settings. This issue affects: Bitdefender Endpoint Security Tools for Windows versions prior to 6.6.18.261. This issue affects: Bitdefender Endpoint Security Tools for Windows versions prior to 6.6.18.261. Bitdefender Endpoint Security SDK versions prior to 6.6.18.261.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2020

CVE-2020-24223

Publication date:
30/08/2020
Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.
Severity CVSS v4.0: Pending analysis
Last modification:
08/11/2022

CVE-2020-24917

Publication date:
30/08/2020
osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.
Severity CVSS v4.0: Pending analysis
Last modification:
03/09/2020

CVE-2020-14352

Publication date:
30/08/2020
A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the targeted system via path traversal. This flaw could potentially result in system compromise via the overwriting of critical system files. The highest threat from this flaw is to users that make use of untrusted third-party repositories.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-8244

Publication date:
30/08/2020
A buffer over-read vulnerability exists in bl
Severity CVSS v4.0: Pending analysis
Last modification:
24/05/2022

CVE-2020-7712

Publication date:
30/08/2020
This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-24972

Publication date:
29/08/2020
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-24898

Publication date:
29/08/2020
The Table Filter and Charts for Confluence Server app before 5.3.26 (for Atlassian Confluence) allows SSRF via the "Table from CSV" macro (URL parameter).
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2020