Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-40648

Publication date:
09/09/2022
In man2html 1.6g, a filename can be created to overwrite the previous size parameter of the next chunk and the fd, bk, fd_nextsize, bk_nextsize of the current chunk. The next chunk is then freed later on, causing a freeing of an arbitrary amount of memory.
Severity CVSS v4.0: Pending analysis
Last modification:
14/09/2022

CVE-2021-40647

Publication date:
09/09/2022
In man2html 1.6g, a specific string being read in from a file will overwrite the size parameter in the top chunk of the heap. This at least causes the program to segmentation abort if the heap size parameter isn't aligned correctly. In version before GLIBC version 2.29 and aligned correctly, it allows arbitrary write anywhere in the programs memory.
Severity CVSS v4.0: Pending analysis
Last modification:
08/08/2023

CVE-2022-39809

Publication date:
09/09/2022
An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/mediation_secure_vault/properties/ajaxprocessor.jsp via the name parameter. Session hijacking or similar attacks would not be possible.
Severity CVSS v4.0: Pending analysis
Last modification:
14/09/2022

CVE-2022-39810

Publication date:
09/09/2022
An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/ndatasource/validateconnection/ajaxprocessor.jsp via the driver parameter. Session hijacking or similar attacks would not be possible.
Severity CVSS v4.0: Pending analysis
Last modification:
14/09/2022

CVE-2022-40317

Publication date:
09/09/2022
OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element.
Severity CVSS v4.0: Pending analysis
Last modification:
14/09/2022

CVE-2022-38615

Publication date:
09/09/2022
SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/service_group.jsf.
Severity CVSS v4.0: Pending analysis
Last modification:
14/09/2022

CVE-2022-38614

Publication date:
09/09/2022
An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files via modifying the PATH parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
14/09/2022

CVE-2022-38613

Publication date:
09/09/2022
A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system.
Severity CVSS v4.0: Pending analysis
Last modification:
14/09/2022

CVE-2022-28742

Publication date:
09/09/2022
aEnrich eHRD Learning Management Key Performance Indicator System 5+ has Improper Access Control. The web application does not validate user session when accessing many application pages. This can allow an attacker to gain unauthenticated access to sensitive functionalities in the application
Severity CVSS v4.0: Pending analysis
Last modification:
14/09/2022

CVE-2022-28740

Publication date:
09/09/2022
aEnrich eHRD Learning Management Key Performance Indicator System 5+ exposes Sensitive Information to an Unauthorized Actor.
Severity CVSS v4.0: Pending analysis
Last modification:
14/09/2022

CVE-2022-36617

Publication date:
09/09/2022
Arq Backup 7.19.5.0 and below stores backup encryption passwords using reversible encryption. This issue allows attackers with administrative privileges to recover cleartext passwords.
Severity CVSS v4.0: Pending analysis
Last modification:
14/09/2022

CVE-2022-28741

Publication date:
09/09/2022
aEnrich a+HRD 5.x Learning Management Key Performance Indicator System has a local file inclusion (LFI) vulnerability that occurs due to missing input validation in v5.x
Severity CVSS v4.0: Pending analysis
Last modification:
08/08/2023