Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-16312

Publication date:
14/09/2019
s-cms V3.0 has XSS in index.php?type=text via the S_id parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
16/09/2019

CVE-2019-16309

Publication date:
14/09/2019
FlameCMS 3.3.5 has SQL injection in account/login.php via accountName.
Severity CVSS v4.0: Pending analysis
Last modification:
16/09/2019

CVE-2019-16310

Publication date:
14/09/2019
NIUSHOP V1.11 has XSS via the index.php?s=/admin URI.
Severity CVSS v4.0: Pending analysis
Last modification:
16/09/2019

CVE-2019-16311

Publication date:
14/09/2019
NIUSHOP V1.11 has CSRF via search_info to index.php.
Severity CVSS v4.0: Pending analysis
Last modification:
16/09/2019

CVE-2019-16313

Publication date:
14/09/2019
ifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-16305

Publication date:
14/09/2019
In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup asking whether the user wants to run MobaXterm to handle the link. If accepted, another popup appears asking for further confirmation. If this is also accepted, command execution is achieved, as demonstrated by the MobaXterm://`calc` URI.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-16303

Publication date:
14/09/2019
A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an insecure source of randomness (apache.commons.lang3 RandomStringUtils). This allows an attacker (if able to obtain their own password reset URL) to compute the value for all other password resets for other accounts, thus allowing privilege escalation or account takeover.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-5484

Publication date:
13/09/2019
Bower before 1.8.8 has a path traversal vulnerability permitting file write in arbitrary locations via install command, which allows attackers to write arbitrary files when a malicious package is extracted.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-5485

Publication date:
13/09/2019
NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository name.
Severity CVSS v4.0: Pending analysis
Last modification:
28/02/2023

CVE-2019-11660

Publication date:
13/09/2019
Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, 10.40. This vulnerability could be exploited by a low-privileged user to execute a custom binary with higher privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-16293

Publication date:
13/09/2019
The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field.
Severity CVSS v4.0: Pending analysis
Last modification:
13/09/2019

CVE-2019-5315

Publication date:
13/09/2019
A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated user to execute arbitrary commands on the underlying operating system. A malicious administrator could use this ability to install backdoors or change system configuration in a way that would not be logged. This vulnerability only affects ArubaOS 8.x.
Severity CVSS v4.0: Pending analysis
Last modification:
16/09/2019