Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-27297

Publication date:
26/01/2021
The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to manipulate memory with controlled values and remotely execute code on the OPC UA Tunneller (versions prior to 6.3.0.8233).
Severity CVSS v4.0: Pending analysis
Last modification:
03/02/2021

CVE-2020-27274

Publication date:
26/01/2021
Some parsing functions in the affected product do not check the return value of malloc and the thread handling the message is forced to close, which may lead to a denial-of-service condition on the OPC UA Tunneller (versions prior to 6.3.0.8233).
Severity CVSS v4.0: Pending analysis
Last modification:
03/02/2021

CVE-2020-13582

Publication date:
26/01/2021
A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
07/06/2022

CVE-2021-3286

Publication date:
26/01/2021
SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variation of the payload may be used. NOTE: this issue exists because of an incomplete fix for CVE-2020-35545.
Severity CVSS v4.0: Pending analysis
Last modification:
30/01/2021

CVE-2021-3304

Publication date:
26/01/2021
Sagemcom F@ST 3686 v2 3.495 devices have a buffer overflow via a long sessionKey to the goform/login URI.
Severity CVSS v4.0: Pending analysis
Last modification:
03/02/2021

CVE-2021-3297

Publication date:
26/01/2021
On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.
Severity CVSS v4.0: Pending analysis
Last modification:
03/02/2021

CVE-2021-3285

Publication date:
26/01/2021
jxbrowser in TI Code Composer Studio IDE 8.x through 10.x before 10.1.1 does not verify X.509 certificates for HTTPS.
Severity CVSS v4.0: Pending analysis
Last modification:
03/02/2021

CVE-2021-3291

Publication date:
26/01/2021
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command.
Severity CVSS v4.0: Pending analysis
Last modification:
09/03/2021

CVE-2021-3278

Publication date:
26/01/2021
Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection . Using this vulnerability, an attacker can bypass the login page.
Severity CVSS v4.0: Pending analysis
Last modification:
26/04/2022

CVE-2021-3223

Publication date:
26/01/2021
Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.
Severity CVSS v4.0: Pending analysis
Last modification:
28/01/2021

CVE-2021-3193

Publication date:
26/01/2021
Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated attacker to execute remote code as the apache user.
Severity CVSS v4.0: Pending analysis
Last modification:
03/02/2021

CVE-2021-3188

Publication date:
26/01/2021
phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.
Severity CVSS v4.0: Pending analysis
Last modification:
03/02/2021