Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-45890

Publication date:
27/12/2021
basic/BasicAuthProvider.java in AuthGuard before 0.9.0 allows authentication via an inactive identifier.
Severity CVSS v4.0: Pending analysis
Last modification:
07/01/2022

CVE-2021-33017

Publication date:
27/12/2021
The standard access path of the IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) requires authentication, but the product has an alternate path or channel that does not require authentication.
Severity CVSS v4.0: Pending analysis
Last modification:
10/01/2022

CVE-2021-4161

Publication date:
27/12/2021
The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login credential details. This could give an attacker admin rights through the HTTP web server.
Severity CVSS v4.0: Pending analysis
Last modification:
07/01/2022

CVE-2021-43857

Publication date:
27/12/2021
Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched in version 0.9.8.
Severity CVSS v4.0: Pending analysis
Last modification:
07/01/2022

CVE-2021-32993

Publication date:
27/12/2021
IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) contains hard-coded credentials, such as a password or a cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
Severity CVSS v4.0: Pending analysis
Last modification:
10/01/2022

CVE-2021-21750

Publication date:
27/12/2021
ZTE BigVideo Analysis product has a privilege escalation vulnerability. Due to improper management of the timed task modification privilege, an attacker with ordinary user permissions could exploit this vulnerability to gain unauthorized access.
Severity CVSS v4.0: Pending analysis
Last modification:
12/01/2022

CVE-2021-43548

Publication date:
27/12/2021
Patient Information Center iX (PIC iX) Versions C.02 and C.03 receives input or data, but does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.
Severity CVSS v4.0: Pending analysis
Last modification:
12/01/2022

CVE-2021-43550

Publication date:
27/12/2021
The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information, which affects the communications between Patient Information Center iX (PIC iX) Versions C.02 and C.03 and Efficia CM Series Revisions A.01 to C.0x and 4.0.
Severity CVSS v4.0: Pending analysis
Last modification:
12/01/2022

CVE-2021-43552

Publication date:
27/12/2021
The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from the Patient Information Center iX (PIC iX) Versions B.02, C.02, and C.03.
Severity CVSS v4.0: Pending analysis
Last modification:
12/01/2022

CVE-2021-23244

Publication date:
27/12/2021
ColorOS pregrant dangerous permissions to apps which are listed in a whitelist xml named default-grant-permissions.But some apps in whitelist is not installed, attacker can disguise app with the same package name to obtain dangerous permission.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2022

CVE-2021-35232

Publication date:
27/12/2021
Hard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with local access to the Web Help Desk host machine allows to execute arbitrary HQL queries against the database and leverage the vulnerability to steal the password hashes of the users or insert arbitrary data into the database.
Severity CVSS v4.0: Pending analysis
Last modification:
17/09/2024

CVE-2021-21751

Publication date:
27/12/2021
ZTE BigVideo analysis product has an input verification vulnerability. Due to the inconsistency between the front and back verifications when configuring the large screen page, an attacker with high privileges could exploit this vulnerability to tamper with the URL and cause service exception.
Severity CVSS v4.0: Pending analysis
Last modification:
08/08/2023