Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-29702

Publication date:
16/06/2021
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200658.
Severity CVSS v4.0: Pending analysis
Last modification:
20/09/2021

CVE-2020-22201

Publication date:
16/06/2021
phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/product.php.
Severity CVSS v4.0: Pending analysis
Last modification:
29/09/2022

CVE-2021-20488

Publication date:
16/06/2021
IBM Security Identity Manager 6.0.2 could allow an authenticated malicious user to change the passwords of other users in the Windows AD environment when IBM Security Identity Manager Windows Password Synch Plug-in is deployed and configured. IBM X-Force ID: 197789.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2022

CVE-2020-22200

Publication date:
16/06/2021
Directory Traversal vulnerability in phpCMS 9.1.13 via the q parameter to public_get_suggest_keyword.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2021

CVE-2020-22199

Publication date:
16/06/2021
SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php.
Severity CVSS v4.0: Pending analysis
Last modification:
21/06/2021

CVE-2021-20567

Publication date:
16/06/2021
IBM Resilient SOAR V38.0 could allow a local privileged attacker to obtain sensitive information due to improper or nonexisting encryption.IBM X-Force ID: 199239.
Severity CVSS v4.0: Pending analysis
Last modification:
21/06/2021

CVE-2021-20566

Publication date:
16/06/2021
IBM Resilient SOAR V38.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 199238.
Severity CVSS v4.0: Pending analysis
Last modification:
21/06/2021

CVE-2021-20483

Publication date:
16/06/2021
IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 197591.
Severity CVSS v4.0: Pending analysis
Last modification:
21/06/2021

CVE-2020-35762

Publication date:
16/06/2021
bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2021

CVE-2020-24939

Publication date:
16/06/2021
Prototype pollution in Stampit supermixer 1.0.3 allows an attacker to modify the prototype of a base object which can vary in severity depending on the implementation.
Severity CVSS v4.0: Pending analysis
Last modification:
02/12/2022

CVE-2020-20444

Publication date:
16/06/2021
Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET parameter in '/shared/view_source.php' which "could" lead to RCE vulnerability .
Severity CVSS v4.0: Pending analysis
Last modification:
29/09/2022

CVE-2020-27339

Publication date:
16/06/2021
In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize parameters, allowing callers to corrupt either the firmware or the OS memory. The fixed versions for this issue in the AhciBusDxe, IdeBusDxe, NvmExpressDxe, SdHostDriverDxe, and SdMmcDeviceDxe drivers are 05.16.25, 05.26.25, 05.35.25, 05.43.25, and 05.51.25 (for Kernel 5.1 through 5.5).
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2022