Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-22260

Publication date:
13/05/2022
The kernel module has a UAF vulnerability.Successful exploitation of this vulnerability will affect data integrity and availability.
Severity CVSS v4.0: Pending analysis
Last modification:
23/05/2022

CVE-2021-46788

Publication date:
13/05/2022
Third-party pop-up window coverage vulnerability in the iConnect module.Successful exploitation of this vulnerability may cause system pop-up window may be covered to mislead users to perform incorrect operations.
Severity CVSS v4.0: Pending analysis
Last modification:
23/05/2022

CVE-2021-46787

Publication date:
13/05/2022
The AMS module has a vulnerability of improper permission control.Successful exploitation of this vulnerability may cause non-system application processes to crash.
Severity CVSS v4.0: Pending analysis
Last modification:
23/05/2022

CVE-2021-46786

Publication date:
13/05/2022
The audio module has a vulnerability in verifying the parameters passed by the application space.Successful exploitation of this vulnerability may cause out-of-bounds memory access.
Severity CVSS v4.0: Pending analysis
Last modification:
23/05/2022

CVE-2022-25591

Publication date:
13/05/2022
BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to delete files within the web server root directory via a crafted HTTP request.
Severity CVSS v4.0: Pending analysis
Last modification:
23/05/2022

CVE-2021-46785

Publication date:
13/05/2022
The Property module has a vulnerability in permission control.This vulnerability can be exploited to obtain the unique device identifier.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2022

CVE-2022-1714

Publication date:
13/05/2022
Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.
Severity CVSS v4.0: Pending analysis
Last modification:
29/06/2023

CVE-2022-30375

Publication date:
13/05/2022
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to file deletion via /sns/classes/Master.php?f=delete_img.
Severity CVSS v4.0: Pending analysis
Last modification:
23/05/2022

CVE-2022-30367

Publication date:
13/05/2022
Air Cargo Management System v1.0 is vulnerable to file deletion via /acms/classes/Master.php?f=delete_img.
Severity CVSS v4.0: Pending analysis
Last modification:
23/05/2022

CVE-2022-30379

Publication date:
13/05/2022
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/?page=user/manage_user&id=.
Severity CVSS v4.0: Pending analysis
Last modification:
23/05/2022

CVE-2022-30378

Publication date:
13/05/2022
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/?page=posts/view_post&id=.
Severity CVSS v4.0: Pending analysis
Last modification:
23/05/2022

CVE-2022-30376

Publication date:
13/05/2022
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/members/view_member.php?id=.
Severity CVSS v4.0: Pending analysis
Last modification:
23/05/2022