Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-28872

Publication date:
12/05/2022
A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website could make a phishing attack with address bar spoofing as the address bar was not correct if navigation fails in a loop.
Severity CVSS v4.0: Pending analysis
Last modification:
23/05/2022

CVE-2022-28873

Publication date:
12/05/2022
A vulnerability affecting F-Secure SAFE browser was discovered. An attacker can potentially exploit Javascript window.open functionality in SAFE Browser which could lead address bar spoofing attacks.
Severity CVSS v4.0: Pending analysis
Last modification:
23/05/2022

CVE-2022-1674

Publication date:
12/05/2022
NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 in GitHub repository vim/vim prior to 8.2.4938. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 allows attackers to cause a denial of service (application crash) via a crafted input.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2022-1650

Publication date:
12/05/2022
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
02/08/2023

CVE-2022-29927

Publication date:
12/05/2022
In JetBrains TeamCity before 2022.04 reflected XSS on the Build Chain Status page was possible
Severity CVSS v4.0: Pending analysis
Last modification:
23/05/2022

CVE-2022-29928

Publication date:
12/05/2022
In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible
Severity CVSS v4.0: Pending analysis
Last modification:
23/05/2022

CVE-2022-29929

Publication date:
12/05/2022
In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible
Severity CVSS v4.0: Pending analysis
Last modification:
23/05/2022

CVE-2022-29930

Publication date:
12/05/2022
SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.
Severity CVSS v4.0: Pending analysis
Last modification:
28/11/2022

CVE-2022-1682

Publication date:
12/05/2022
Reflected Xss using url based payload in GitHub repository neorazorx/facturascripts prior to 2022.07. Xss can use to steal user&amp;#39;s cookies which lead to Account takeover or do any malicious activity in victim&amp;#39;s browser
Severity CVSS v4.0: Pending analysis
Last modification:
21/05/2022

CVE-2022-1044

Publication date:
12/05/2022
Sensitive Data Exposure Due To Insecure Storage Of Profile Image in GitHub repository polonel/trudesk prior to v1.2.1.
Severity CVSS v4.0: Pending analysis
Last modification:
20/05/2022

CVE-2022-1681

Publication date:
12/05/2022
Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions
Severity CVSS v4.0: Pending analysis
Last modification:
20/05/2022

CVE-2022-29885

Publication date:
12/05/2022
The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.
Severity CVSS v4.0: Pending analysis
Last modification:
06/04/2023