Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-30063

Publication date:
03/04/2022
On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Security Appliance, crafted OPC packets can cause an OPC enforcer denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
09/04/2022

CVE-2021-30065

Publication date:
03/04/2022
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, crafted ModBus packets can bypass the ModBus enforcer. NOTE: this issue exists because of an incomplete fix of CVE-2017-11401.
Severity CVSS v4.0: Pending analysis
Last modification:
09/04/2022

CVE-2021-30064

Publication date:
03/04/2022
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH login can succeed with hardcoded default credentials (if the device is in the uncommissioned state).
Severity CVSS v4.0: Pending analysis
Last modification:
09/04/2022

CVE-2022-28389

Publication date:
03/04/2022
mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2022-28388

Publication date:
03/04/2022
usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free.
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2025

CVE-2022-28391

Publication date:
03/04/2022
BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.
Severity CVSS v4.0: Pending analysis
Last modification:
09/06/2025

CVE-2022-28390

Publication date:
03/04/2022
ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free.
Severity CVSS v4.0: Pending analysis
Last modification:
25/06/2025

CVE-2022-28381

Publication date:
03/04/2022
Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrary code via a long string to TCP port 888, a related issue to CVE-2017-17932.
Severity CVSS v4.0: Pending analysis
Last modification:
09/04/2022

CVE-2022-0405

Publication date:
03/04/2022
Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16.
Severity CVSS v4.0: Pending analysis
Last modification:
19/11/2024

CVE-2022-0406

Publication date:
03/04/2022
Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.
Severity CVSS v4.0: Pending analysis
Last modification:
19/11/2024

CVE-2022-28378

Publication date:
03/04/2022
Craft CMS before 3.7.29 allows XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2022

CVE-2022-28379

Publication date:
03/04/2022
jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2022