Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-16712

Publication date:
26/09/2018
IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send a specially crafted IOCTL 0x9C406104 to read physical memory.
Severity CVSS v4.0: Pending analysis
Last modification:
27/12/2018

CVE-2018-16713

Publication date:
26/09/2018
IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send an IOCTL (0x9C402084) with a buffer containing user defined content. The driver's subroutine will execute a rdmsr instruction with the user's buffer for input, and provide output from the instruction.
Severity CVSS v4.0: Pending analysis
Last modification:
27/12/2018

CVE-2018-15531

Publication date:
26/09/2018
JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java.
Severity CVSS v4.0: Pending analysis
Last modification:
29/11/2018

CVE-2018-14327

Publication date:
26/09/2018
The installer for the Alcatel OSPREY3_MINI Modem component on EE EE40VB 4G mobile broadband modems with firmware before EE40_00_02.00_45 sets weak permissions (Everyone:Full Control) for the "Web Connecton\EE40" and "Web Connecton\EE40\BackgroundService" directories, which allows local users to gain privileges, as demonstrated by inserting a Trojan horse ServiceManager.exe file into the "Web Connecton\EE40\BackgroundService" directory.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-16055

Publication date:
26/09/2018
An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to its passing user input from the $_POST parameters "ifdescr" and "ipv" to a shell without escaping the contents of the variables. This allows an authenticated WebGUI user with privileges for the affected page to execute commands in the context of the root user when submitting a request to relinquish a DHCP lease for an interface which is configured to obtain its address via DHCP.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-16588

Publication date:
26/09/2018
Privilege escalation can occur in the SUSE useradd.c code in useradd, as distributed in the SUSE shadow package through 4.2.1-27.9.1 for SUSE Linux Enterprise 12 (SLE-12) and through 4.5-5.39 for SUSE Linux Enterprise 15 (SLE-15). Non-existing intermediate directories are created with mode 0777 during user creation. Given that they are world-writable, local attackers might use this for privilege escalation and other unspecified attacks. NOTE: this would affect non-SUSE users who took useradd.c code from a 2014-04-02 upstream pull request; however, no non-SUSE distribution is known to be affected.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-17365

Publication date:
26/09/2018
SeaCMS 6.64 and 7.2 allows remote attackers to delete arbitrary files via the filedir parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
19/04/2022

CVE-2018-17410

Publication date:
26/09/2018
Horus CMS allows SQL Injection, as demonstrated by a request to the /busca or /home URI.
Severity CVSS v4.0: Pending analysis
Last modification:
14/04/2020

CVE-2018-17566

Publication date:
26/09/2018
In ThinkPHP 5.1.24, the inner function delete can be used for SQL injection when its WHERE condition's value can be controlled by a user's request.
Severity CVSS v4.0: Pending analysis
Last modification:
20/11/2018

CVE-2018-16969

Publication date:
26/09/2018
Citrix ShareFile StorageZones Controller before 5.4.2 has Information Exposure Through an Error Message.
Severity CVSS v4.0: Pending analysis
Last modification:
23/11/2018

CVE-2018-16968

Publication date:
26/09/2018
Citrix ShareFile StorageZones Controller before 5.4.2 allows Directory Traversal.
Severity CVSS v4.0: Pending analysis
Last modification:
23/11/2018

CVE-2018-17081

Publication date:
26/09/2018
e107 2.1.9 allows CSRF via e107_admin/wmessage.php?mode=&action=inline&ajax_used=1&id= for changing the title of an arbitrary page.
Severity CVSS v4.0: Pending analysis
Last modification:
26/11/2018