Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-9686

Publication date:
11/03/2019
pacman before 5.1.3 allows directory traversal when installing a remote package via a specified URL "pacman -U " due to an unsanitized file name received from a Content-Disposition header. pacman renames the downloaded package file to match the name given in this header. However, pacman did not sanitize this name, which may contain slashes, before calling rename(). A malicious server (or a network MitM if downloading over HTTP) can send a Content-Disposition header to make pacman place the file anywhere in the filesystem, potentially leading to arbitrary root code execution. Notably, this bypasses pacman's package signature checking. This occurs in curl_download_internal in lib/libalpm/dload.c.
Severity CVSS v4.0: Pending analysis
Last modification:
09/11/2020

CVE-2019-9687

Publication date:
11/03/2019
PoDoFo 0.9.6 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfString.cpp.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-9659

Publication date:
11/03/2019
The Chuango 433 MHz burglar-alarm product line uses static codes in the RF remote control, allowing an attacker to arm, disarm, or trigger the alarm remotely via replay attacks, as demonstrated by Chuango branded products, and non-Chuango branded products such as the Eminent EM8617 OV2 Wifi Alarm System.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2019-9675

Publication date:
11/03/2019
An issue was discovered in PHP 7.x before 7.1.27 and 7.3.x before 7.3.3. phar_tar_writeheaders_int in ext/phar/tar.c has a buffer overflow via a long link value. NOTE: The vendor indicates that the link value is used only when an archive contains a symlink, which currently cannot happen: "This issue allows theoretical compromise of security, but a practical attack is usually impossible.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2024

CVE-2019-9660

Publication date:
11/03/2019
Stored XSS exists in YzmCMS 5.2 via the admin/category/edit.html "catname" parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
11/03/2019

CVE-2019-9661

Publication date:
11/03/2019
Stored XSS exists in YzmCMS 5.2 via the admin/system_manage/user_config_edit.html "value" parameter,
Severity CVSS v4.0: Pending analysis
Last modification:
11/03/2019

CVE-2019-9656

Publication date:
11/03/2019
An issue was discovered in LibOFX 0.9.14. There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump.
Severity CVSS v4.0: Pending analysis
Last modification:
20/01/2023

CVE-2019-9662

Publication date:
11/03/2019
An issue was discovered in JTBC(PHP) 3.0.1.8. Its cache management module is flawed. An arbitrary file ending in "inc.php" can be deleted via a console/cache/manage.php?type=action&action=batch&batch=delete&ids=../ substring.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-9658

Publication date:
11/03/2019
Checkstyle before 8.18 loads external DTDs by default.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-9650

Publication date:
11/03/2019
An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name for an event.
Severity CVSS v4.0: Pending analysis
Last modification:
26/03/2019

CVE-2019-9652

Publication date:
11/03/2019
There is a CSRF in SDCMS V1.7 via an m=admin&c=theme&a=edit request. It allows PHP code injection by providing a filename in the file parameter, and providing file content in the t2 parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
11/03/2019

CVE-2019-9651

Publication date:
11/03/2019
An issue was discovered in SDCMS V1.7. In the \app\admin\controller\themecontroller.php file, the check_bad() function's filtering is not strict, resulting in PHP code execution. This occurs because some dangerous PHP functions (such as "eval") are blocked but others (such as "system") are not, and because ".php" is blocked but ".PHP" is not blocked.
Severity CVSS v4.0: Pending analysis
Last modification:
11/03/2019