Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-46372

Publication date:
12/01/2023
Alotcer - AR7088H-A firmware version 16.10.3 Command execution Improper validation of unspecified input field may allow Authenticated command execution.
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2025

CVE-2022-39187

Publication date:
12/01/2023
Rumpus - FTP server version 9.0.7.1 has a Reflected cross-site scripting (RXSS) vulnerability through unspecified vectors.
Severity CVSS v4.0: Pending analysis
Last modification:
20/01/2023

CVE-2022-39185

Publication date:
12/01/2023
EXFO - BV-10 Performance Endpoint Unit Undocumented privileged user. Unit has an undocumented hard-coded privileged user.
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2025

CVE-2013-10011

Publication date:
12/01/2023
A vulnerability was found in aeharding classroom-engagement-system and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to sql injection. The attack may be launched remotely. The name of the patch is 096de5815c7b414e7339f3439522a446098fb73a. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218156.
Severity CVSS v4.0: Pending analysis
Last modification:
17/05/2024

CVE-2012-10005

Publication date:
12/01/2023
A vulnerability has been found in manikandan170890 php-form-builder-class and classified as problematic. Affected by this vulnerability is an unknown functionality of the file PFBC/Element/Textarea.php of the component Textarea Handler. The manipulation of the argument value leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The patch is named 74897993818d826595fd5857038e6703456a594a. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218155.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2022-39183

Publication date:
12/01/2023
Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.
Severity CVSS v4.0: Pending analysis
Last modification:
20/01/2023

CVE-2022-39186

Publication date:
12/01/2023
EXFO - BV-10 Performance Endpoint Unit misconfiguration. System configuration file has misconfigured permissions
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2025

CVE-2022-39182

Publication date:
12/01/2023
H C Mingham-Smith Ltd - Tardis 2000 Privilege escalation.Version 1.6 is vulnerable to privilege escalation which may allow a malicious actor to gain system privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2025

CVE-2022-39184

Publication date:
12/01/2023
EXFO - BV-10 Performance Endpoint Unit authentication bypass User can manually manipulate access enabling authentication bypass.
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2025

CVE-2022-3437

Publication date:
12/01/2023
A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack.
Severity CVSS v4.0: Pending analysis
Last modification:
28/10/2024

CVE-2022-3592

Publication date:
12/01/2023
A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' escape the configured share path. This flaw allows a remote user with access to the exported part of the file system under a share via SMB1 unix extensions or NFS to create symlinks to files outside the 'smbd' configured share path and gain access to another restricted server's filesystem.
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2025

CVE-2022-3515

Publication date:
12/01/2023
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2025