Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-20364

Publication date:
14/09/2022
In sysmmu_unmap of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-233606615References: N/A
Severity CVSS v4.0: Pending analysis
Last modification:
10/11/2022

CVE-2022-20231

Publication date:
14/09/2022
In smc_intc_request_fiq of arm_gic.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-211485702References: N/A
Severity CVSS v4.0: Pending analysis
Last modification:
10/11/2022

CVE-2022-38796

Publication date:
14/09/2022
A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by abusing password reset emails.
Severity CVSS v4.0: Pending analysis
Last modification:
16/09/2022

CVE-2022-3202

Publication date:
14/09/2022
A NULL pointer dereference flaw in diFree in fs/jfs/inode.c in Journaled File System (JFS)in the Linux kernel. This could allow a local attacker to crash the system or leak kernel internal information.
Severity CVSS v4.0: Pending analysis
Last modification:
05/10/2023

CVE-2022-22520

Publication date:
14/09/2022
A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2.
Severity CVSS v4.0: Pending analysis
Last modification:
01/10/2022

CVE-2022-37661

Publication date:
14/09/2022
SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature.
Severity CVSS v4.0: Pending analysis
Last modification:
20/01/2023

CVE-2022-40674

Publication date:
14/09/2022
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
Severity CVSS v4.0: Pending analysis
Last modification:
30/05/2025

CVE-2022-40626

Publication date:
14/09/2022
An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in order to create a fake account with predefined login, password and role in Zabbix Frontend.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2022-40673

Publication date:
14/09/2022
KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2022-37140

Publication date:
14/09/2022
PayMoney 3.3 is vulnerable to Client Side Remote Code Execution (RCE). The vulnerability exists on the reply ticket function and upload the malicious file. A calculator will open when the victim who download the file open the RTF file.
Severity CVSS v4.0: Pending analysis
Last modification:
16/09/2022

CVE-2022-37137

Publication date:
14/09/2022
PayMoney 3.3 is vulnerable to Stored Cross-Site Scripting (XSS) during replying the ticket. The XSS can be obtain from injecting under "Message" field with "description" parameter with the specially crafted payload to gain Stored XSS. The XSS then will prompt after that or can be access from the view ticket function.
Severity CVSS v4.0: Pending analysis
Last modification:
04/06/2025

CVE-2022-37138

Publication date:
14/09/2022
Loan Management System 1.0 is vulnerable to SQL Injection at the login page, which allows unauthorized users to login as Administrator after injecting username form.
Severity CVSS v4.0: Pending analysis
Last modification:
26/11/2024