Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-9073

Publication date:
24/02/2019
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an attempted excessive memory allocation in _bfd_elf_slurp_version_tables in elf.c.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-9074

Publication date:
24/02/2019
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an out-of-bounds read leading to a SEGV in bfd_getl32 in libbfd.c, when called from pex64_get_runtime_function in pei-x86_64.c.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-9075

Publication date:
24/02/2019
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is a heap-based buffer overflow in _bfd_archive_64_bit_slurp_armap in archive64.c.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-9076

Publication date:
24/02/2019
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an attempted excessive memory allocation in elf_read_notes in elf.c.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-9077

Publication date:
24/02/2019
An issue was discovered in GNU Binutils 2.32. It is a heap-based buffer overflow in process_mips_specific in readelf.c via a malformed MIPS option section.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-9047

Publication date:
23/02/2019
GoRose v1.0.4 has SQL Injection when the order_by or group_by parameter can be controlled.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-9062

Publication date:
23/02/2019
PHP Scripts Mall Online Food Ordering Script 1.0 has Cross-Site Request Forgery (CSRF) in my-account.php.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-9063

Publication date:
23/02/2019
PHP Scripts Mall Auction website script 2.0.4 allows parameter tampering of the payment amount.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-9064

Publication date:
23/02/2019
PHP Scripts Mall Cab Booking Script 1.0.3 allows Directory Traversal into the parent directory of a jpg or png file.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-9065

Publication date:
23/02/2019
PHP Scripts Mall Custom T-Shirt Ecommerce Script 3.1.1 allows parameter tampering of the payment amount.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-9066

Publication date:
23/02/2019
PHP Scripts Mall PHP Appointment Booking Script 3.0.3 allows HTML injection in a user profile.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2019-9048

Publication date:
23/02/2019
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete a theme (aka topic) via a /admin.php?action=theme_delete&var1= URI.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026