Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-27949

Publication date:
15/03/2021
Cross-site Scripting vulnerability in MyBB before 1.8.26 via Custom moderator tools.
Severity CVSS v4.0: Pending analysis
Last modification:
16/03/2021

CVE-2021-27948

Publication date:
15/03/2021
SQL Injection vulnerability in MyBB before 1.8.26 via User Groups. (issue 3 of 3).
Severity CVSS v4.0: Pending analysis
Last modification:
16/03/2021

CVE-2021-27947

Publication date:
15/03/2021
SQL Injection vulnerability in MyBB before 1.8.26 via the Copy Forum feature in Forum Management. (issue 2 of 3).
Severity CVSS v4.0: Pending analysis
Last modification:
16/03/2021

CVE-2021-27890

Publication date:
15/03/2021
SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
Severity CVSS v4.0: Pending analysis
Last modification:
21/09/2021

CVE-2021-20286

Publication date:
15/03/2021
A flaw was found in libnbd 1.7.3. An assertion failure in nbd_unlocked_opt_go in ilb/opt.c may lead to denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
22/03/2021

CVE-2020-28149

Publication date:
15/03/2021
myDBR 5.8.3/4262 is affected by: Cross Site Scripting (XSS). The impact is: execute arbitrary code (remote). The component is: CSRF Token. The attack vector is: CSRF token injection to XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
24/03/2021

CVE-2020-29555

Publication date:
15/03/2021
The BackupDelete functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to delete arbitrary files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be exploited by an unauthenticated attacker due to a lack of CSRF protection.)
Severity CVSS v4.0: Pending analysis
Last modification:
25/03/2021

CVE-2020-29556

Publication date:
15/03/2021
The Backup functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to read arbitrary local files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be exploited by an unauthenticated attacker due to a lack of CSRF protection.)
Severity CVSS v4.0: Pending analysis
Last modification:
25/03/2021

CVE-2021-22191

Publication date:
15/03/2021
Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture file.
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2022

CVE-2020-24982

Publication date:
15/03/2021
An issue was discovered in Quadbase ExpressDashboard (EDAB) 7 Update 9. It allows CSRF. An attacker may be able to trick an authenticated user into changing the email address associated with their account.
Severity CVSS v4.0: Pending analysis
Last modification:
21/05/2021

CVE-2020-24985

Publication date:
15/03/2021
An issue was discovered in Quadbase EspressReports ES 7 Update 9. An authenticated user is able to navigate to the MenuPage section of the application, and change the frmsrc parameter value to retrieve and execute external files or payloads.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2022

CVE-2021-25676

Publication date:
15/03/2021
A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE S615 (V6.3), SCALANCE SC-600 (All Versions >= V2.1 and
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2021