Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-10063

Publication date:
12/04/2018
The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that is mishandled when exporting a Leads file.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-3861

Publication date:
12/04/2018
A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
03/02/2023

CVE-2018-3862

Publication date:
12/04/2018
A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting
Severity CVSS v4.0: Pending analysis
Last modification:
28/11/2022

CVE-2018-3868

Publication date:
12/04/2018
A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
03/02/2023

CVE-2018-3889

Publication date:
12/04/2018
A specially crafted PCX image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a PCX image to trigger this vulnerability and gain code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
03/02/2023

CVE-2018-10073

Publication date:
12/04/2018
joyplus-cms 1.6.0 has XSS in manager/admin_vod.php via the keyword parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
14/05/2018

CVE-2018-10072

Publication date:
12/04/2018
windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a 0x953827bf DeviceIoControl call.
Severity CVSS v4.0: Pending analysis
Last modification:
17/10/2018

CVE-2018-10071

Publication date:
12/04/2018
windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a 0x953826DB DeviceIoControl call.
Severity CVSS v4.0: Pending analysis
Last modification:
17/10/2018

CVE-2018-10068

Publication date:
12/04/2018
The jDownloads extension before 3.2.59 for Joomla! has XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
15/05/2018

CVE-2018-10074

Publication date:
12/04/2018
The hi3660_stub_clk_probe function in drivers/clk/hisilicon/clk-hi3660-stub.c in the Linux kernel before 4.16 allows local users to cause a denial of service (NULL pointer dereference) by triggering a failure of resource retrieval.
Severity CVSS v4.0: Pending analysis
Last modification:
22/05/2018

CVE-2018-1079

Publication date:
12/04/2018
pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The REST interface of the pcsd service did not properly sanitize the file name from the /remote/put_file query. If the /etc/booth directory exists, an authenticated attacker with write permissions could create or overwrite arbitrary files with arbitrary data outside of the /etc/booth directory, in the context of the pcsd process.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2018-1084

Publication date:
12/04/2018
corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c.
Severity CVSS v4.0: Pending analysis
Last modification:
31/01/2023