Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-4031

Publication date:
31/10/2019
An exploitable vulnerability exists in the safe browsing function of the CUJO Smart Firewall, version 7003. The flaw lies in the way the safe browsing function parses HTTP requests. The server hostname is extracted from captured HTTP/HTTPS requests and inserted as part of a Lua statement without prior sanitization, which results in arbitrary Lua script execution in the kernel. An attacker could send an HTTP request to exploit this vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-4064

Publication date:
31/10/2019
An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause a unverified device configuration change, resulting in an unverified change of the user password on the device. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-13508

Publication date:
31/10/2019
FreeTDS through 1.1.11 has a Buffer Overflow.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-13547

Publication date:
31/10/2019
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the IP address to use the function without authentication.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-13551

Publication date:
31/10/2019
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path traversal vulnerabilities are caused by a lack of proper validation of a user-supplied path prior to use in file operations. An attacker can leverage these vulnerabilities to remotely execute code while posing as an administrator.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2012-6123

Publication date:
31/10/2019
Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."
Severity CVSS v4.0: Pending analysis
Last modification:
18/08/2020

CVE-2012-6122

Publication date:
31/10/2019
Buffer overflow in the thread scheduler in Chicken before 4.8.0.1 allows attackers to cause a denial of service (crash) by opening a file descriptor with a large integer value.
Severity CVSS v4.0: Pending analysis
Last modification:
05/11/2019

CVE-2012-6125

Publication date:
31/10/2019
Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.
Severity CVSS v4.0: Pending analysis
Last modification:
05/11/2019

CVE-2010-2783

Publication date:
31/10/2019
IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2010-2548

Publication date:
31/10/2019
IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2012-6124

Publication date:
31/10/2019
A casting error in Chicken before 4.8.0 on 64-bit platform caused the random number generator to return a constant value. NOTE: the vendor states "This function wasn't used for security purposes (and is advertised as being unsuitable)."
Severity CVSS v4.0: Pending analysis
Last modification:
06/11/2019

CVE-2019-18396

Publication date:
31/10/2019
An issue was discovered in certain Oi third-party firmware that may be installed on Technicolor TD5130v2 devices. A Command Injection in the Ping module in the Web Interface in OI_Fw_V20 allows remote attackers to execute arbitrary OS commands in the pingAddr parameter to mnt_ping.cgi. NOTE: This may overlap CVE-2017–14127.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026