Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-19291

Publication date:
15/11/2018
An issue was discovered in DiliCMS 2.4.0. There is a CSRF vulnerability that can delete a user or group via an admin/index.php/user/del/1 or admin/index.php/role/del/2 URI.
Severity CVSS v4.0: Pending analysis
Last modification:
16/04/2019

CVE-2018-19287

Publication date:
15/11/2018
XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
14/12/2018

CVE-2015-9274

Publication date:
15/11/2018
HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (invalid read of two bytes and application crash) because of GPOS and GSUB table mishandling, related to hb-ot-layout-gpos-table.hh, hb-ot-layout-gsub-table.hh, and hb-ot-layout-gsubgpos-private.hh.
Severity CVSS v4.0: Pending analysis
Last modification:
18/12/2018

CVE-2018-19289

Publication date:
15/11/2018
An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2018-19286

Publication date:
15/11/2018
The server in mubu note 2018-11-11 has XSS by configuring an account with a crafted name value (along with an arbitrary username value), and then creating and sharing a note.
Severity CVSS v4.0: Pending analysis
Last modification:
25/06/2020

CVE-2018-19288

Publication date:
15/11/2018
Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API.
Severity CVSS v4.0: Pending analysis
Last modification:
04/05/2021

CVE-2018-19279

Publication date:
14/11/2018
PRIMX ZoneCentral before 6.1.2236 on Windows sometimes leaks the plaintext of NTFS files. On non-SSD devices, this is limited to a 5-second window and file sizes less than 600 bytes. The effect on SSD devices may be greater.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-19280

Publication date:
14/11/2018
Centreon 3.4.x (fixed in Centreon 18.10.0) has XSS via the resource name or macro expression of a poller macro.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2019

CVE-2018-19281

Publication date:
14/11/2018
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2019

CVE-2018-19278

Publication date:
14/11/2018
Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 16.0.1 allows remote attackers to crash Asterisk via a specially crafted DNS SRV or NAPTR response, because a buffer size is supposed to match an expanded length but actually matches a compressed length.
Severity CVSS v4.0: Pending analysis
Last modification:
30/12/2018

CVE-2018-17960

Publication date:
14/11/2018
CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2019

CVE-2018-5495

Publication date:
14/11/2018
All StorageGRID Webscale versions are susceptible to a vulnerability which could permit an unauthenticated attacker to communicate with systems on the same network as the StorageGRID Webscale Admin Node via HTTP or to take over services on the Admin Node.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019