Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2002-1427

Publication date:
11/04/2003
The print_html_to_file function in edit.cgi for Easy Homepage Creator 1.0 does not check user credentials, which allows remote attackers to modify home pages of other users.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2002-1428

Publication date:
11/04/2003
index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2002-1429

Publication date:
11/04/2003
Cross-site scripting vulnerability in board.php of endity.com ShoutBOX allows remote attackers to inject arbitrary HTML into the shoutbox page via the site parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2002-1430

Publication date:
11/04/2003
Unknown vulnerability in Sympoll 1.2 allows remote attackers to read arbitrary files when register_globals is enabled, possibly by modifying certain PHP variables through URL parameters.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2002-1431

Publication date:
11/04/2003
Belkin F5D5230-4 4-Port Cable/DSL Gateway Router 1.20.000 modifies the source IP address of internal packets to that of the router's external interface when forwarding a request from an internal host to an internal web server, which allows remote attackers to hide which host is being used to access the web server.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2002-1432

Publication date:
11/04/2003
MidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensitive information by directly requesting the database.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2002-1433

Publication date:
11/04/2003
Kerio MailServer 5.0 allows remote attackers to cause a denial of service (hang) via SYN packets to the supported network services.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2002-1434

Publication date:
11/04/2003
Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attackers to execute HTML script as other users via certain URLs.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2002-1435

Publication date:
11/04/2003
class.atkdateattribute.js.php in Achievo 0.7.0 through 0.9.1, except 0.8.2, allows remote attackers to execute arbitrary PHP code when the 'allow_url_fopen' setting is enabled via a URL in the config_atkroot parameter that points to the code.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2002-1436

Publication date:
11/04/2003
The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary Perl code via an HTTP POST request.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2002-1438

Publication date:
11/04/2003
The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to obtain Perl version information via the -v option.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2002-1439

Publication date:
11/04/2003
Unknown vulnerability related to stack corruption in the TGA daemon for HP-UX 11.04 (VVOS) Virtualvault 4.0, 4.5, and 4.6 may allow attackers to obtain access to system files.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025