Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-22329

Publication date:
13/09/2022
IBM Control Desk 7.6.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 219124.
Severity CVSS v4.0: Pending analysis
Last modification:
16/09/2022

CVE-2022-3205

Publication date:
13/09/2022
Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2022-20398

Publication date:
13/09/2022
In addOrUpdateNetwork of WifiServiceImpl.java, there is a possible way for a guest user to configure Wi-Fi due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-221859734
Severity CVSS v4.0: Pending analysis
Last modification:
19/09/2022

CVE-2022-20386

Publication date:
13/09/2022
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227328
Severity CVSS v4.0: Pending analysis
Last modification:
16/09/2022

CVE-2022-20387

Publication date:
13/09/2022
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227324
Severity CVSS v4.0: Pending analysis
Last modification:
16/09/2022

CVE-2022-20388

Publication date:
13/09/2022
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227323
Severity CVSS v4.0: Pending analysis
Last modification:
05/06/2025

CVE-2022-20389

Publication date:
13/09/2022
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257004
Severity CVSS v4.0: Pending analysis
Last modification:
05/06/2025

CVE-2022-20390

Publication date:
13/09/2022
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257002
Severity CVSS v4.0: Pending analysis
Last modification:
16/09/2022

CVE-2022-20391

Publication date:
13/09/2022
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257000
Severity CVSS v4.0: Pending analysis
Last modification:
16/09/2022

CVE-2022-3182

Publication date:
13/09/2022
Improper Access Control vulnerability in the Duo SMS two-factor of Devolutions Remote Desktop Manager 2022.2.14 and earlier allows attackers to bypass the application lock. This issue affects: Devolutions Remote Desktop Manager version 2022.2.14 and prior versions.
Severity CVSS v4.0: Pending analysis
Last modification:
20/09/2022

CVE-2021-0943

Publication date:
13/09/2022
In MMU_MapPages of TBD, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-238916921
Severity CVSS v4.0: Pending analysis
Last modification:
16/09/2022

CVE-2022-20392

Publication date:
13/09/2022
In declareDuplicatePermission of ParsedPermissionUtils.java, there is a possible way to obtain a dangerous permission without user consent due to improper input validation. This could lead to local escalation of privilege during app installation or upgrade with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-213323615
Severity CVSS v4.0: Pending analysis
Last modification:
05/06/2025