Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-30018

Publication date:
19/05/2022
Mobotix Control Center (MxCC) through 2.5.4.5 has Insufficiently Protected Credentials, Storing Passwords in a Recoverable Format via the MxCC.ini config file. The credential storage method in this software enables an attacker/user of the machine to gain admin access to the software and gain access to recordings/recording locations.
Severity CVSS v4.0: Pending analysis
Last modification:
13/02/2024

CVE-2021-41938

Publication date:
19/05/2022
An issue was discovered in ShopXO CMS 2.2.0. After entering the management page, there is an arbitrary file upload vulnerability in three locations.
Severity CVSS v4.0: Pending analysis
Last modification:
26/05/2022

CVE-2022-1730

Publication date:
19/05/2022
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 18.0.4.
Severity CVSS v4.0: Pending analysis
Last modification:
16/02/2023

CVE-2022-1785

Publication date:
19/05/2022
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.4977.
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2025

CVE-2022-1183

Publication date:
19/05/2022
On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and DNS over HTTPS (DoH), but configurations using DoT alone are unaffected. Affects BIND 9.18.0 -> 9.18.2 and version 9.19.0 of the BIND 9.19 development branch.
Severity CVSS v4.0: Pending analysis
Last modification:
07/10/2022

CVE-2022-1670

Publication date:
19/05/2022
When generating a user invitation code in Octopus Server, the validity of this code can be set for a specific number of users. It was possible to bypass this restriction of validity to create extra user accounts above the initial number of invited users.
Severity CVSS v4.0: Pending analysis
Last modification:
27/07/2022

CVE-2022-28349

Publication date:
19/05/2022
Arm Mali GPU Kernel Driver has a use-after-free: Midgard r28p0 through r29p0 before r30p0, Bifrost r17p0 through r23p0 before r24p0, and Valhall r19p0 through r23p0 before r24p0.
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2022

CVE-2022-28350

Publication date:
19/05/2022
Arm Mali GPU Kernel Driver allows improper GPU operations in Valhall r29p0 through r36p0 before r37p0 to reach a use-after-free situation.
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2022

CVE-2022-28348

Publication date:
19/05/2022
Arm Mali GPU Kernel Driver (Midgard r4p0 through r31p0, Bifrost r0p0 through r36p0 before r37p0, and Valhall r19p0 through r36p0 before r37p0) allows improper GPU memory operations to reach a use-after-free situation.
Severity CVSS v4.0: Pending analysis
Last modification:
13/12/2023

CVE-2022-30138

Publication date:
18/05/2022
Windows Print Spooler Elevation of Privilege Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
02/01/2025

CVE-2022-29230

Publication date:
18/05/2022
Hydrogen is a React-based framework for building dynamic, Shopify-powered custom storefronts. There is a potential Cross-Site Scripting (XSS) vulnerability where an arbitrary user is able to execute scripts on pages that are built with Hydrogen. This affects all versions of Hydrogen starting from version 0.10.0 to 0.18.0. This vulnerability is exploitable in applications whose hydrating data is user controlled. All Hydrogen users should upgrade their project to version 0.19.0. There is no current workaround, and users should update as soon as possible. Additionally, the Content Security Policy is not an effective mitigation for this vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
01/06/2022

CVE-2022-1774

Publication date:
18/05/2022
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7.
Severity CVSS v4.0: Pending analysis
Last modification:
16/02/2023