Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-9567

Publication date:
04/03/2019
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has XSS via a custom input field of a poll.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-9568

Publication date:
04/03/2019
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the attacker has the delete permission.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-9563

Publication date:
04/03/2019
In BlueMind 3.5.x before 3.5.11 Hotfix 7 and 4.x before 4.0-beta3, the contact application mishandles temporary uploads.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-9565

Publication date:
04/03/2019
Druide Antidote RX, HD, 8 before 8.05.2287, 9 before 9.5.3937 and 10 before 10.1.2147 allows remote attackers to steal NTLM hashes or perform SMB relay attacks upon a direct launch of the product, or upon an indirect launch via an integration such as Chrome, Firefox, Word, Outlook, etc. This occurs because the product attempts to access a share with the PLUG-INS subdomain name; an attacker may be able to use Active Directory Domain Services to register that name.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-9551

Publication date:
04/03/2019
An issue was discovered in DOYO (aka doyocms) 2.3 through 2015-05-06. It has admin.php XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-9552

Publication date:
04/03/2019
Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or p2p/images/ URI.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-9549

Publication date:
03/03/2019
An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=user&act=addnew URI, as demonstrated by adding a level=1 account, a similar issue to CVE-2018-18935.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-9550

Publication date:
03/03/2019
DhCms through 2017-09-18 has admin.php?r=admin/Index/index XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-8278

Publication date:
02/03/2019
Stored XSS in Invision Power Board versions 3.3.1 - 3.4.8 leads to Remote Code Execution.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-8279

Publication date:
02/03/2019
Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message on forum.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-9546

Publication date:
01/03/2019
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-9547

Publication date:
01/03/2019
In Storage Performance Development Kit (SPDK) before 19.01, a malicious vhost client (i.e., virtual machine) could carefully construct a circular descriptor chain that would result in a partial denial of service in the SPDK vhost target, because the vhost target did not properly detect such chains.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026