Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-29819

Publication date:
28/04/2022
In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2022

CVE-2022-29820

Publication date:
28/04/2022
In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2022

CVE-2022-29817

Publication date:
28/04/2022
In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2022

CVE-2022-29814

Publication date:
28/04/2022
In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2022

CVE-2022-29815

Publication date:
28/04/2022
In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2022

CVE-2022-29812

Publication date:
28/04/2022
In JetBrains IntelliJ IDEA before 2022.1 notification mechanisms about using Unicode directionality formatting characters were insufficient
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2022

CVE-2022-29813

Publication date:
28/04/2022
In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2022

CVE-2022-29816

Publication date:
28/04/2022
In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible
Severity CVSS v4.0: Pending analysis
Last modification:
28/06/2023

CVE-2022-1509

Publication date:
28/04/2022
Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.
Severity CVSS v4.0: Pending analysis
Last modification:
30/08/2024

CVE-2022-29811

Publication date:
28/04/2022
In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible.
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2022

CVE-2022-28719

Publication date:
28/04/2022
Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the system configuration to upload a crafted configuration file to the managing server, which may result in the managed clients to execute arbitrary code with the administrative privilege.
Severity CVSS v4.0: Pending analysis
Last modification:
09/05/2022

CVE-2022-29869

Publication date:
28/04/2022
cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.
Severity CVSS v4.0: Pending analysis
Last modification:
24/11/2023