Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-40884

Publication date:
19/10/2022
Bento4 1.6.0 has memory leaks via the mp4fragment.
Severity CVSS v4.0: Pending analysis
Last modification:
09/05/2025

CVE-2022-40885

Publication date:
19/10/2022
Bento4 v1.6.0-639 has a memory allocation issue that can cause denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
09/05/2025

CVE-2022-3586

Publication date:
19/10/2022
A flaw was found in the Linux kernel’s networking code. A use-after-free was found in the way the sch_sfb enqueue function used the socket buffer (SKB) cb field after the same SKB had been enqueued (and freed) into a child qdisc. This flaw allows a local, unprivileged user to crash the system, causing a denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
25/06/2025

CVE-2022-43014

Publication date:
19/10/2022
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
24/09/2025

CVE-2022-43015

Publication date:
19/10/2022
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
24/09/2025

CVE-2022-43016

Publication date:
19/10/2022
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component.
Severity CVSS v4.0: Pending analysis
Last modification:
24/09/2025

CVE-2022-43017

Publication date:
19/10/2022
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.
Severity CVSS v4.0: Pending analysis
Last modification:
24/09/2025

CVE-2022-43019

Publication date:
19/10/2022
OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.
Severity CVSS v4.0: Pending analysis
Last modification:
24/09/2025

CVE-2022-43018

Publication date:
19/10/2022
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email function.
Severity CVSS v4.0: Pending analysis
Last modification:
24/09/2025

CVE-2022-43020

Publication date:
19/10/2022
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update function.
Severity CVSS v4.0: Pending analysis
Last modification:
24/09/2025

CVE-2022-43021

Publication date:
19/10/2022
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable.
Severity CVSS v4.0: Pending analysis
Last modification:
24/09/2025

CVE-2022-43022

Publication date:
19/10/2022
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.
Severity CVSS v4.0: Pending analysis
Last modification:
24/09/2025