Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2017-7931

Publication date:
06/06/2018
In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access the configuration files and application pages without authentication.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2018-7510

Publication date:
06/06/2018
In the web application in BeaconMedaes TotalAlert Scroll Medical Air Systems running software versions prior to 4107600010.23, passwords are presented in plaintext in a file that is accessible without authentication.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2018-1000203

Publication date:
06/06/2018
Soar Labs Soar Coin version up to and including git commit 4a2aa71ee21014e2880a3f7aad11091ed6ad434f (latest release as of Sept 2017) contains an intentional backdoor vulnerability in the function zero_fee_transaction() that can result in theft of Soar Coins by the "onlycentralAccount" (Soar Labs) after payment is processed.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-1456

Publication date:
06/06/2018
IBM Rhapsody DM 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 140091.
Severity CVSS v4.0: Pending analysis
Last modification:
24/07/2018

CVE-2017-1480

Publication date:
06/06/2018
IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potentially sensitive information in log files that could be read by a remote user. IBM X-Force ID: 128617.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2017-1474

Publication date:
06/06/2018
IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 128606.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2017-1476

Publication date:
06/06/2018
IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 128610.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2018-11553

Publication date:
06/06/2018
SGIN.CN xiangyun platform V9.4.10 has XSS via the login_url parameter to /login.php.
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2018

CVE-2018-11808

Publication date:
06/06/2018
Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to delete any file and read certain files on the server in the context of the user (which by default is "NT AUTHORITY / SYSTEM") by sending a specially crafted request to the server.
Severity CVSS v4.0: Pending analysis
Last modification:
07/08/2018

CVE-2018-11813

Publication date:
06/06/2018
libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.
Severity CVSS v4.0: Pending analysis
Last modification:
25/06/2020

CVE-2018-7884

Publication date:
05/06/2018
An issue was discovered in DisplayLink Core Software Cleaner Application 8.2.1956. When the drivers are updated to a newer version, the product launches a process as SYSTEM to uninstall the old version: cl_1956.exe is run as SYSTEM on the %systemroot%\Temp folder, where any user can write a DLL (e.g., version.dll) to perform DLL Hijacking and elevate privileges to SYSTEM.
Severity CVSS v4.0: Pending analysis
Last modification:
01/08/2018

CVE-2017-7635

Publication date:
05/06/2018
QNAP NAS application Proxy Server through version 1.2.0 does not utilize CSRF protections.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2018