Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2004-1648

Publication date:
31/08/2004
Cross-site scripting (XSS) vulnerability in (1) index.asp, (2) ChangePassword.asp, (3) users_list.asp, (4) and users_add.asp in Password Protect allows remote attackers to inject arbitrary web script or HTML via the ShowMsg parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1649

Publication date:
31/08/2004
Buffer overflow in Microsoft Msinfo32.exe might allow local users to execute arbitrary code via a long filename in the msinfo_file command line parameter. NOTE: this issue might not cross security boundaries, so it may be REJECTED in the future.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1650

Publication date:
31/08/2004
D-Link DCS-900 Internet Camera listens on UDP port 62976 for an IP address, which allows remote attackers to change the IP address of the camera via a UDP broadcast packet.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1651

Publication date:
31/08/2004
Multiple cross-site scripting (XSS) vulnerabilities in the registration page in phpScheduleIt 1.0.0 RC1 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Lastname fields during new user registration, or (3) the Schedule Name field.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1652

Publication date:
31/08/2004
phpScheduleIt 1.0.0 RC1 does not clear administrative privileges if the administrator logs in as a normal user, which allows users with physical access to gain administrative privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1653

Publication date:
31/08/2004
The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configured with an anonymous access program such as AnonCVS.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1660

Publication date:
30/08/2004
PHP remote file inclusion vulnerability in CuteNews 1.3.6 and earlier allows remote attackers to execute arbitrary PHP code via the cutepath parameter to (1) show_archives.php or (2) show_news.php.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1644

Publication date:
30/08/2004
Xedus 1.0 allows remote attackers to cause a denial of service (refuse connections) by connecting multiple times from the same IP address.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1645

Publication date:
30/08/2004
Cross-site scripting (XSS) vulnerability in Xedus 1.0 allows remote attackers to execute arbitrary web script or HTML via the (1) username parameter to test.x, (2) username parameter to TestServer.x, or (3) param parameter to testgetrequest.x.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1646

Publication date:
30/08/2004
Directory traversal vulnerability in Xedus 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1647

Publication date:
30/08/2004
SQL injection vulnerability in Password Protect allows remote attackers to execute arbitrary SQL statements and bypass authentication via (1) admin or Pass parameter to index_next.asp, (2) LoginId, OPass, or NPass to CPassChangePassword.asp, (3) users_edit.asp, or (4) users_add.asp.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1641

Publication date:
29/08/2004
Heap-based buffer overflow in Titan FTP 3.21 and earlier allows remote attackers to cause a denial of service (crash) via a long FTP command such as (1) CWD, (2) STAT, or (3) LIST.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025