Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2017-9136

Publication date:
21/05/2017
An issue was discovered on Mimosa Client Radios before 2.2.3. In the device's web interface, there is a page that allows an attacker to use an unsanitized GET parameter to download files from the device as the root user. The attacker can download any file from the device's filesystem. This can be used to view unsalted, MD5-hashed administrator passwords, which can then be cracked, giving the attacker full admin access to the device's web interface. This vulnerability can also be used to view the plaintext pre-shared key (PSK) for encrypted wireless connections, or to view the device's serial number (which allows an attacker to factory reset the device).
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-9137

Publication date:
21/05/2017
Ceragon FibeAir IP-10 wireless radios through 7.2.0 have a default password of mateidu for the mateidu account (a hidden user account established by the vendor). This account can be accessed via both the web interface and SSH. In the web interface, this simply grants an attacker read-only access to the device's settings. However, when using SSH, this gives an attacker access to a Linux shell. NOTE: the vendor has commented "The mateidu user is a known user, which is mentioned in the FibeAir IP-10 User Guide. Customers are instructed to change the mateidu user password. Changing the user password fully solves the vulnerability."
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-9117

Publication date:
21/05/2017
In LibTIFF 4.0.6 and possibly other versions, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, as demonstrated by a heap-based buffer over-read in bmp2tiff. NOTE: mentioning bmp2tiff does not imply that the activation point is in the bmp2tiff.c file (which was removed before the 4.0.7 release).
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-9119

Publication date:
21/05/2017
The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application crash) or possibly have unspecified other impact by triggering crafted operations on array data structures.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2014-9970

Publication date:
21/05/2017
jasypt before 1.9.2 allows a timing attack against the password hash comparison.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-9101

Publication date:
21/05/2017
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header and PHP code in the name of a file.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-9110

Publication date:
21/05/2017
In OpenEXR 2.2.0, an invalid read of size 2 in the hufDecode function in ImfHuf.cpp could cause the application to crash.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-9111

Publication date:
21/05/2017
In OpenEXR 2.2.0, an invalid write of size 8 in the storeSSE function in ImfOptimizedPixelReading.h could cause the application to crash or execute arbitrary code.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-9112

Publication date:
21/05/2017
In OpenEXR 2.2.0, an invalid read of size 1 in the getBits function in ImfHuf.cpp could cause the application to crash.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-9113

Publication date:
21/05/2017
In OpenEXR 2.2.0, an invalid write of size 1 in the bufferedReadPixels function in ImfInputFile.cpp could cause the application to crash or execute arbitrary code.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-9114

Publication date:
21/05/2017
In OpenEXR 2.2.0, an invalid read of size 1 in the refill function in ImfFastHuf.cpp could cause the application to crash.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-9115

Publication date:
21/05/2017
In OpenEXR 2.2.0, an invalid write of size 2 in the = operator function in half.h could cause the application to crash or execute arbitrary code.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026