Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-1976

Publication date:
12/02/2020
A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect software running on Mac OS allows authenticated local users to cause the Mac OS kernel to hang or crash. This issue affects GlobalProtect 5.0.5 and earlier versions of GlobalProtect 5.0 on Mac OS.
Severity CVSS v4.0: Pending analysis
Last modification:
04/05/2020

CVE-2020-6975

Publication date:
12/02/2020
Digi International ConnectPort LTS 32 MEI, Firmware Version 1.4.3 (82002228_K 08/09/2018), bios Version 1.2. Successful exploitation of this vulnerability could allow an attacker to upload a malicious file to the application.
Severity CVSS v4.0: Pending analysis
Last modification:
21/02/2020

CVE-2020-1975

Publication date:
12/02/2020
Missing XML validation vulnerability in the PAN-OS web interface on Palo Alto Networks PAN-OS software allows authenticated users to inject arbitrary XML that results in privilege escalation. This issue affects PAN-OS 8.1 versions earlier than PAN-OS 8.1.12 and PAN-OS 9.0 versions earlier than PAN-OS 9.0.6. This issue does not affect PAN-OS 7.1, PAN-OS 8.0, or PAN-OS 9.1 or later versions.
Severity CVSS v4.0: Pending analysis
Last modification:
18/02/2020

CVE-2020-1977

Publication date:
12/02/2020
Insufficient Cross-Site Request Forgery (XSRF) protection on Expedition Migration Tool allows remote unauthenticated attackers to hijack the authentication of administrators and to perform actions on the Expedition Migration Tool. This issue affects Expedition Migration Tool 1.1.51 and earlier versions.
Severity CVSS v4.0: Pending analysis
Last modification:
30/12/2021

CVE-2020-8955

Publication date:
12/02/2020
irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a malformed IRC message 324 (channel mode).
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2011-4908

Publication date:
12/02/2020
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2013-6022

Publication date:
12/02/2020
A Cross-Site Scripting (XSS) vulnerability exists in Tiki Wiki CMG Groupware 11.0 via the id paraZeroClipboard.swf, which could let a remote malicious user execute arbitrary code.
Severity CVSS v4.0: Pending analysis
Last modification:
18/02/2020

CVE-2013-5106

Publication date:
12/02/2020
A Code Execution vulnerability exists in select.py when using python-mode 2012-12-19.
Severity CVSS v4.0: Pending analysis
Last modification:
19/02/2020

CVE-2013-4602

Publication date:
12/02/2020
A Denial of Service (infinite loop) vulnerability exists in Avira AntiVir Engine before 8.2.12.58 via an unspecified function in the PDF Scanner Engine.
Severity CVSS v4.0: Pending analysis
Last modification:
18/02/2020

CVE-2020-5399

Publication date:
12/02/2020
Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with access to the network between CredHub and its MySQL database may eavesdrop on database connections and thereby gain unauthorized access to CredHub and other components.
Severity CVSS v4.0: Pending analysis
Last modification:
27/02/2020

CVE-2011-4906

Publication date:
12/02/2020
Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2020-8950

Publication date:
12/02/2020
The AUEPLauncher service in Radeon AMD User Experience Program Launcher through 1.0.0.1 on Windows allows elevation of privilege by placing a crafted file in %PROGRAMDATA%\AMD\PPC\upload and then creating a symbolic link in %PROGRAMDATA%\AMD\PPC\temp that points to an arbitrary folder with an arbitrary file name.
Severity CVSS v4.0: Pending analysis
Last modification:
19/02/2020