Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2017-11439

Publication date:
19/07/2017
In Sitecore 8.2, there is reflected XSS in the shell/Applications/Tools/Run Program parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2017-11440

Publication date:
19/07/2017
In Sitecore 8.2, there is absolute path traversal via the shell/Applications/Layouts/IDE.aspx fi parameter and the admin/LinqScratchPad.aspx Reference parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2017-11456

Publication date:
19/07/2017
Geneko GWR routers allow directory traversal sequences starting with a /../ substring, as demonstrated by unauthenticated read access to the configuration file.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2017-10801

Publication date:
19/07/2017
phpSocial (formerly phpDolphin) before 3.0.1 has XSS in the PATH_INFO to the search/tag/ URI.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2017-11435

Publication date:
19/07/2017
The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management console. The bug is exploitable remotely when the router is configured to expose the management console. The router is not validating the session token while returning answers for some methods in url '/api'. An attacker can use this vulnerability to retrieve sensitive information such as private/public IP addresses, SSID names, and passwords.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2017-11436

Publication date:
19/07/2017
D-Link DIR-615 before v20.12PTb04 has a second admin account with a 0x1 BACKDOOR value, which might allow remote attackers to obtain access via a TELNET connection.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2017-11448

Publication date:
19/07/2017
The ReadJPEGImage function in coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted file.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2017-11449

Publication date:
19/07/2017
coders/mpc.c in ImageMagick before 7.0.6-1 does not enable seekable streams and thus cannot validate blob sizes, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an image received from stdin.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2017-11450

Publication date:
19/07/2017
coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via JPEG data that is too short.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2017-11446

Publication date:
19/07/2017
The ReadPESImage function in coders\pes.c in ImageMagick 7.0.6-1 has an infinite loop vulnerability that can cause CPU exhaustion via a crafted PES file.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2017-11447

Publication date:
19/07/2017
The ReadSCREENSHOTImage function in coders/screenshot.c in ImageMagick before 7.0.6-1 has memory leaks, causing denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2017-9245

Publication date:
19/07/2017
The Google News and Weather application before 3.3.1 for Android allows remote attackers to read OAuth tokens by sniffing the network and leveraging the lack of SSL.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025