Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-43029

Publication date:
19/10/2022
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the time parameter at /goform/SetSysTimeCfg.
Severity CVSS v4.0: Pending analysis
Last modification:
08/05/2025

CVE-2022-41708

Publication date:
19/10/2022
Relatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access existing chats in the workspaces of any user of the application. This is possible because the application does not validate permissions correctly.
Severity CVSS v4.0: Pending analysis
Last modification:
08/05/2025

CVE-2022-43028

Publication date:
19/10/2022
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the timeZone parameter at /goform/SetSysTimeCfg.
Severity CVSS v4.0: Pending analysis
Last modification:
08/05/2025

CVE-2022-43027

Publication date:
19/10/2022
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the firewallEn parameter at /goform/SetFirewallCfg.
Severity CVSS v4.0: Pending analysis
Last modification:
08/05/2025

CVE-2022-43026

Publication date:
19/10/2022
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the endIp parameter at /goform/SetPptpServerCfg.
Severity CVSS v4.0: Pending analysis
Last modification:
09/05/2025

CVE-2022-43025

Publication date:
19/10/2022
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the startIp parameter at /goform/SetPptpServerCfg.
Severity CVSS v4.0: Pending analysis
Last modification:
09/05/2025

CVE-2022-43024

Publication date:
19/10/2022
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.
Severity CVSS v4.0: Pending analysis
Last modification:
09/05/2025

CVE-2022-43023

Publication date:
19/10/2022
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.
Severity CVSS v4.0: Pending analysis
Last modification:
24/09/2025

CVE-2022-42227

Publication date:
19/10/2022
jsonlint 1.0 is vulnerable to heap-buffer-overflow via /home/hjsz/jsonlint/src/lexer.
Severity CVSS v4.0: Pending analysis
Last modification:
08/05/2025

CVE-2022-40884

Publication date:
19/10/2022
Bento4 1.6.0 has memory leaks via the mp4fragment.
Severity CVSS v4.0: Pending analysis
Last modification:
09/05/2025

CVE-2022-40885

Publication date:
19/10/2022
Bento4 v1.6.0-639 has a memory allocation issue that can cause denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
09/05/2025

CVE-2022-3586

Publication date:
19/10/2022
A flaw was found in the Linux kernel’s networking code. A use-after-free was found in the way the sch_sfb enqueue function used the socket buffer (SKB) cb field after the same SKB had been enqueued (and freed) into a child qdisc. This flaw allows a local, unprivileged user to crash the system, causing a denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
25/06/2025