Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-41218

Publication date:
21/09/2022
In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount races, affecting dvb_demux_open and dvb_dmxdev_release.
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2025

CVE-2022-41220

Publication date:
21/09/2022
md2roff 1.9 has a stack-based buffer overflow via a Markdown file, a different vulnerability than CVE-2022-34913. NOTE: the vendor's position is that the product is not intended for untrusted input
Severity CVSS v4.0: Pending analysis
Last modification:
09/04/2025

CVE-2022-38619

Publication date:
21/09/2022
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf.
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2025

CVE-2022-35090

Publication date:
21/09/2022
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via __asan_memcpy at /asan/asan_interceptors_memintrinsics.cpp:.
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2025

CVE-2022-35089

Publication date:
21/09/2022
SWFTools commit 772e55a2 was discovered to contain a heap-buffer-overflow via getTransparentColor at /home/bupt/Desktop/swftools/src/gif2swf.
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2025

CVE-2022-35085

Publication date:
21/09/2022
SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c.
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2025

CVE-2022-35088

Publication date:
21/09/2022
SWFTools commit 772e55a2 was discovered to contain a heap buffer-overflow via getGifDelayTime at /home/bupt/Desktop/swftools/src/src/gif2swf.c.
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2025

CVE-2022-39221

Publication date:
21/09/2022
McWebserver mod runs a simple HTTP server alongside the Minecraft server in seperate threads. Path traversal in McWebserver Minecraft Mod for Fabric and Quilt up to and including 0.1.2.1 and McWebserver Minecraft Mod for Forge up to and including 0.1.1 allows all files, accessible by the program, to be read by anyone via HTTP request. Version 0.2.0 with patches are released to both platforms (Fabric and Quilt, Forge). As a workaround, the McWebserver mod can be disabled by removing the file from the `mods` directory.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2022

CVE-2022-35086

Publication date:
21/09/2022
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via /multiarch/memmove-vec-unaligned-erms.S.
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2025

CVE-2022-35087

Publication date:
21/09/2022
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via MovieAddFrame at /src/gif2swf.c.
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2025

CVE-2022-35957

Publication date:
20/09/2022
Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to server admin when auth proxy is used, allowing an admin to take over the server admin account and gain full control of the grafana instance. All installations should be upgraded as soon as possible. As a workaround deactivate auth proxy following the instructions at: https://grafana.com/docs/grafana/latest/setup-grafana/configure-security/configure-authentication/auth-proxy/
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2022-39220

Publication date:
20/09/2022
SFTPGo is an SFTP server written in Go. Versions prior to 2.3.5 are subject to Cross-site scripting (XSS) vulnerabilities in the SFTPGo WebClient, allowing remote attackers to inject malicious code. This issue is patched in version 2.3.5. No known workarounds exist.
Severity CVSS v4.0: Pending analysis
Last modification:
22/09/2022