Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-13156

Publication date:
23/06/2020
modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=user_add URI.
Severity CVSS v4.0: Pending analysis
Last modification:
29/06/2020

CVE-2020-13157

Publication date:
23/06/2020
modules\users\admin\edit.php in NukeViet 4.4 allows CSRF to change a user's password via an admin/index.php?nv=users&op=edit&userid= URI. The old password is not needed.
Severity CVSS v4.0: Pending analysis
Last modification:
29/06/2020

CVE-2020-13155

Publication date:
23/06/2020
clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=clearsystem URI.
Severity CVSS v4.0: Pending analysis
Last modification:
29/06/2020

CVE-2020-14974

Publication date:
23/06/2020
The driver in IOBit Unlocker 1.1.2 allows a low-privileged user to unlock a file and kill processes (even ones running as SYSTEM) that hold a handle, via IOCTL code 0x222124.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-14975

Publication date:
23/06/2020
The driver in IOBit Unlocker 1.1.2 allows a low-privileged user to delete, move, or copy arbitrary files via IOCTL code 0x222124.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-14976

Publication date:
23/06/2020
GNS3 ubridge through 0.9.18 on macOS, as used in GNS3 server before 2.1.17, allows a local attacker to read arbitrary files because it handles configuration-file errors by printing the configuration file while executing in a setuid root context.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-14073

Publication date:
23/06/2020
XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can create a map, and then use the Map Designer Properties screen to insert JavaScript code. This can be exploited against any user with View Maps or Edit Maps access.
Severity CVSS v4.0: Pending analysis
Last modification:
27/01/2023

CVE-2020-7664

Publication date:
23/06/2020
In all versions of the package github.com/unknwon/cae/zip, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.
Severity CVSS v4.0: Pending analysis
Last modification:
21/12/2021

CVE-2020-7668

Publication date:
23/06/2020
In all versions of the package github.com/unknwon/cae/tz, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.
Severity CVSS v4.0: Pending analysis
Last modification:
01/01/2022

CVE-2020-4188

Publication date:
23/06/2020
IBM Security Guardium 10.6 and 11.1 may use insufficiently random numbers or values in a security context that depends on unpredictable numbers. IBM X-Force ID: 174807.
Severity CVSS v4.0: Pending analysis
Last modification:
02/07/2020

CVE-2020-11068

Publication date:
23/06/2020
In LoRaMac-node before 4.4.4, a reception buffer overflow can happen due to the received buffer size not being checked. This has been fixed in 4.4.4.
Severity CVSS v4.0: Pending analysis
Last modification:
01/07/2020

CVE-2020-9438

Publication date:
23/06/2020
Tinxy Door Lock with firmware before 3.2 allow attackers to unlock a door by replaying an Unlock request that occurred when the attacker was previously authorized. In other words, door-access revocation is mishandled.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023