Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2012-5655

Publication date:
03/01/2013
The Context module 6.x-3.x before 6.x-3.1 and 7.x-3.x before 7.x-3.0-beta6 for Drupal does not properly restrict access to block content, which allows remote attackers to obtain sensitive information via a crafted request.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2025

CVE-2012-5654

Publication date:
03/01/2013
The Nodewords: D6 Meta Tags module before 6.x-1.14 for Drupal, when configured to automatically generate description meta tags from node text, does not properly filter node content when creating tags, which might allow remote attackers to obtain sensitive information by reading the (1) description, (2) dc.description or (3) og:description meta tags.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2025

CVE-2012-5666

Publication date:
03/01/2013
Cross-site scripting (XSS) vulnerability in bookmarks/js/bookmarks.js in ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to apps/bookmark/index.php.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2025

CVE-2012-5651

Publication date:
03/01/2013
Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2025

CVE-2012-5652

Publication date:
03/01/2013
Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2025

CVE-2012-5653

Publication date:
03/01/2013
The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2025

CVE-2012-5665

Publication date:
03/01/2013
ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 does not properly restrict access to settings.php, which allows remote attackers to edit app configurations of user_webdavauth and user_ldap by editing this file.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2025

CVE-2012-4545

Publication date:
03/01/2013
The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotiate authentication, delegates user credentials through GSSAPI, which allows remote servers to authenticate as the client via the delegated credentials.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2025

CVE-2012-2379

Publication date:
03/01/2013
Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2025

CVE-2012-6469

Publication date:
02/01/2013
Opera before 12.11 allows remote attackers to determine the existence of arbitrary local files via vectors involving web script in an error page.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2025

CVE-2012-6470

Publication date:
02/01/2013
Opera before 12.12 does not properly allocate memory for GIF images, which allows remote attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a malformed image.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2025

CVE-2012-6471

Publication date:
02/01/2013
Opera before 12.12 allows remote attackers to spoof the address field via a high rate of HTTP requests.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2025