Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-44082

Publication date:
29/03/2022
textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger remote code execution by uploading a webshell. To do so they must first steal the CSRF token before submitting a file upload request.
Severity CVSS v4.0: Pending analysis
Last modification:
06/04/2022

CVE-2022-26871

Publication date:
29/03/2022
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
22/12/2025

CVE-2022-21821

Publication date:
29/03/2022
NVIDIA CUDA Toolkit SDK contains an integer overflow vulnerability in cuobjdump.To exploit this vulnerability, a remote attacker would require a local user to download a specially crafted, corrupted file and locally execute cuobjdump against the file. Such an attack may lead to remote code execution that causes complete denial of service and an impact on data confidentiality and integrity.
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2022

CVE-2021-42911

Publication date:
29/03/2022
A Format String vulnerability exists in DrayTek Vigor 2960
Severity CVSS v4.0: Pending analysis
Last modification:
05/04/2022

CVE-2021-43118

Publication date:
29/03/2022
A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a crafted HTTP message containing malformed QUERY STRING in mainfunction.cgi, which could let a remote malicious user execute arbitrary code.
Severity CVSS v4.0: Pending analysis
Last modification:
05/04/2022

CVE-2022-22948

Publication date:
29/03/2022
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.
Severity CVSS v4.0: Pending analysis
Last modification:
31/10/2025

CVE-2021-43109

Publication date:
29/03/2022
An SQL Injection vulnerability exits in PuneethReddyHC online-shopping-system as of 11/01/2021 via the p parameter in product.php.
Severity CVSS v4.0: Pending analysis
Last modification:
06/04/2022

CVE-2021-43110

Publication date:
29/03/2022
An Access Conrol vulnerability exists in PuneethReddyHC online-shopping-system as of 11/01/2021 in add_products.
Severity CVSS v4.0: Pending analysis
Last modification:
06/04/2022

CVE-2021-42970

Publication date:
29/03/2022
Cross Site Scripting (XSS) vulnerability exists in cxuucms v3 via the imgurl of /feedback/post/ content parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
04/04/2022

CVE-2022-1122

Publication date:
29/03/2022
A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2025

CVE-2022-26839

Publication date:
29/03/2022
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect default permission in the DIAEnergie application, which may allow an attacker to plant new files (such as DLLs) or replace existing executable files.
Severity CVSS v4.0: Pending analysis
Last modification:
04/04/2022

CVE-2022-27175

Publication date:
29/03/2022
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetCalcTagList. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
Severity CVSS v4.0: Pending analysis
Last modification:
01/04/2022