Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-12102

Publication date:
11/06/2018
md4c 0.2.6 has a NULL pointer dereference in the function md_process_line in md4c.c, related to ctx->current_block.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-12108

Publication date:
11/06/2018
An issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress function in validation.cc allows remote attackers to cause a denial of service (SIGFPE and application crash) via a malformed file.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-12109

Publication date:
11/06/2018
An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The TransformPaletteC::process function in transform/palette_C.hpp allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PAM image file.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-12110

Publication date:
11/06/2018
portfolioCMS 1.0.5 has SQL Injection via the admin/portfolio.php preview parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-12111

Publication date:
11/06/2018
Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /wt3/mydocs.php URI.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-12092

Publication date:
11/06/2018
tinyexr 0.9.5 has a heap-based buffer over-read in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-12093

Publication date:
11/06/2018
tinyexr 0.9.5 has a memory leak in ParseEXRHeaderFromMemory in tinyexr.h.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-12094

Publication date:
11/06/2018
Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-12095

Publication date:
11/06/2018
A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerability is located in the mod parameter of info.php.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-12099

Publication date:
11/06/2018
Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-12100

Publication date:
11/06/2018
Sonatype Nexus Repository Manager versions 3.x before 3.12.0 has XSS in multiple areas in the Administration UI.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-10360

Publication date:
11/06/2018
The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026