Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-10068

Publication date:
26/03/2019
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service to bypass the initial authentication and proceed to deserialize user-controlled .NET object input. This deserialization then led to unauthenticated remote code execution on the server where the Kentico instance was hosted.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-3597

Publication date:
26/03/2019
Authentication Bypass vulnerability in McAfee Network Security Manager (NSM) 9.1
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-3606

Publication date:
26/03/2019
Data Leakage Attacks vulnerability in the web portal component when in an MDR pair in McAfee Network Security Management (NSM) 9.1
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-3804

Publication date:
26/03/2019
It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-3826

Publication date:
26/03/2019
A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-3830

Publication date:
26/03/2019
A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-3848

Publication date:
26/03/2019
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was read-only access, users could not edit the events.)
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-3849

Publication date:
26/03/2019
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-3850

Publication date:
26/03/2019
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header policy made them more susceptible to exploits.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-3851

Publication date:
26/03/2019
A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-3852

Publication date:
26/03/2019
A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-3878

Publication date:
26/03/2019
A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), adding special HTTP headers that are normally used to start the special SAML ECP (non-browser based) can be used to bypass authentication.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026