Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-42136

Publication date:
13/04/2022
A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute JavaScript code in the client's browser by storing said code as a Missing Data Code value. This can then be leveraged to execute a Cross-Site Request Forgery attack to escalate privileges to administrator.
Severity CVSS v4.0: Pending analysis
Last modification:
21/04/2022

CVE-2022-0221

Publication date:
13/04/2022
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information disclosure when opening a malicious solution file provided by an attacker with SCADAPack Workbench. This could be exploited to pass data from local files to a remote system controlled by an attacker. Affected Product: SCADAPack Workbench (6.6.8a and prior)
Severity CVSS v4.0: Pending analysis
Last modification:
21/04/2022

CVE-2021-22797

Publication date:
13/04/2022
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file is loaded in the engineering software. Affected Product: EcoStruxure Control Expert (V15.0 SP1 and prior, including former Unity Pro), EcoStruxure Process Expert (2020 and prior, including former HDCS), SCADAPack RemoteConnect for x70 (All versions)
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2022

CVE-2015-20107

Publication date:
13/04/2022
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2025

CVE-2022-28052

Publication date:
13/04/2022
Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege to arbitrarily upload files via /common/upload API, which could lead to remote arbitrary code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
21/04/2022

CVE-2021-46167

Publication date:
13/04/2022
An access control issue in the authentication module of wizplat PD065 v1.19 allows attackers to access sensitive data and cause a Denial of Service (DoS).
Severity CVSS v4.0: Pending analysis
Last modification:
07/10/2022

CVE-2022-26144

Publication date:
13/04/2022
An XSS issue was discovered in MantisBT before 2.25.3. Improper escaping of a Plugin name allows execution of arbitrary code (if CSP allows it) in manage_plugin_page.php and manage_plugin_uninstall.php when a crafted plugin is installed.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2022

CVE-2022-26643

Publication date:
13/04/2022
An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2022

CVE-2022-27256

Publication date:
13/04/2022
A PHP Local File inclusion vulnerability in the Redbasic theme for Hubzilla before version 7.2 allows remote attackers to include arbitrary php files via the schema parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2022

CVE-2021-43741

Publication date:
13/04/2022
CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading to remote code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2022

CVE-2020-29653

Publication date:
13/04/2022
Froxlor through 0.10.22 does not perform validation on user input passed in the customermail GET parameter. The value of this parameter is reflected in the login webpage, allowing the injection of arbitrary HTML tags.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2022

CVE-2022-24308

Publication date:
13/04/2022
Automox Agent prior to version 37 on Windows and Linux and Version 36 on OSX could allow for a non privileged user to obtain sensitive information during the install process.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2022