Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-8434

Publication date:
18/02/2019
In CmsEasy 7.0, there is XSS via the ckplayer.php autoplay parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
19/02/2019

CVE-2019-8429

Publication date:
18/02/2019
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
19/02/2019

CVE-2019-8428

Publication date:
18/02/2019
ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value.
Severity CVSS v4.0: Pending analysis
Last modification:
19/02/2019

CVE-2019-8426

Publication date:
18/02/2019
skins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the newControl[MinTiltRange] parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
19/02/2019

CVE-2019-8425

Publication date:
18/02/2019
includes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages.
Severity CVSS v4.0: Pending analysis
Last modification:
19/02/2019

CVE-2019-8424

Publication date:
18/02/2019
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
19/02/2019

CVE-2019-8423

Publication date:
18/02/2019
ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
19/02/2019

CVE-2019-8436

Publication date:
18/02/2019
imcat 4.5 has Stored XSS via the root/run/adm.php fm[instop][note] parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
19/02/2019

CVE-2019-8433

Publication date:
18/02/2019
JTBC(PHP) 3.0.1.8 allows Arbitrary File Upload via the console/#/console/file/manage.php?type=list URI, as demonstrated by a .php file.
Severity CVSS v4.0: Pending analysis
Last modification:
20/02/2019

CVE-2019-8435

Publication date:
18/02/2019
admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header.
Severity CVSS v4.0: Pending analysis
Last modification:
20/02/2019

CVE-2019-8427

Publication date:
18/02/2019
daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-8419

Publication date:
17/02/2019
VNote 2.2 has XSS via a new text note.
Severity CVSS v4.0: Pending analysis
Last modification:
19/02/2019