Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-38676

Publication date:
14/10/2022
In gpu driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
Severity CVSS v4.0: Pending analysis
Last modification:
15/05/2025

CVE-2022-38677

Publication date:
14/10/2022
In cell service, there is a missing permission check. This could lead to local denial of service in cell service with no additional execution privileges needed.
Severity CVSS v4.0: Pending analysis
Last modification:
15/05/2025

CVE-2022-38671

Publication date:
14/10/2022
In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
Severity CVSS v4.0: Pending analysis
Last modification:
18/10/2022

CVE-2022-38670

Publication date:
14/10/2022
In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
Severity CVSS v4.0: Pending analysis
Last modification:
15/05/2025

CVE-2022-38669

Publication date:
14/10/2022
In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
Severity CVSS v4.0: Pending analysis
Last modification:
15/05/2025

CVE-2022-2985

Publication date:
14/10/2022
In music service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
Severity CVSS v4.0: Pending analysis
Last modification:
15/05/2025

CVE-2022-2984

Publication date:
14/10/2022
In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
Severity CVSS v4.0: Pending analysis
Last modification:
15/05/2025

CVE-2022-2963

Publication date:
14/10/2022
A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.
Severity CVSS v4.0: Pending analysis
Last modification:
15/05/2025

CVE-2022-2850

Publication date:
14/10/2022
A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2025

CVE-2022-42234

Publication date:
14/10/2022
There is a file inclusion vulnerability in the template management module in UCMS 1.6
Severity CVSS v4.0: Pending analysis
Last modification:
14/05/2025

CVE-2022-41303

Publication date:
14/10/2022
A user may be tricked into opening a malicious FBX file which may exploit a use-after-free vulnerability in Autodesk FBX SDK 2020 version causing the application to reference a memory location controlled by an unauthorized third party, thereby running arbitrary code on the system.
Severity CVSS v4.0: Pending analysis
Last modification:
14/05/2025

CVE-2022-41302

Publication date:
14/10/2022
An Out-Of-Bounds Read Vulnerability in Autodesk FBX SDK version 2020. and prior may lead to code execution or information disclosure through maliciously crafted FBX files. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
Severity CVSS v4.0: Pending analysis
Last modification:
14/05/2025