Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-20627

Publication date:
31/08/2020
The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change.
Severity CVSS v4.0: Pending analysis
Last modification:
06/02/2023

CVE-2020-13472

Publication date:
31/08/2020
The flash memory readout protection in Gigadevice GD32F103 devices allows physical attackers to extract firmware via the debug interface by utilizing the DMA module.
Severity CVSS v4.0: Pending analysis
Last modification:
03/09/2020

CVE-2020-13470

Publication date:
31/08/2020
Gigadevice GD32F103 and GD32F130 devices allow physical attackers to extract data via the probing of easily accessible bonding wires and de-obfuscation of the observed data.
Severity CVSS v4.0: Pending analysis
Last modification:
03/09/2020

CVE-2020-13468

Publication date:
31/08/2020
Gigadevice GD32F130 devices allow physical attackers to escalate their debug interface permissions via fault injection into inter-IC bonding wires (which have insufficient physical protection).
Severity CVSS v4.0: Pending analysis
Last modification:
03/09/2020

CVE-2020-13465

Publication date:
31/08/2020
The security protection in Gigadevice GD32F103 devices allows physical attackers to redirect the control flow and execute arbitrary code via the debug interface.
Severity CVSS v4.0: Pending analysis
Last modification:
03/09/2020

CVE-2020-13463

Publication date:
31/08/2020
The flash memory readout protection in Apex Microelectronics APM32F103 devices allows physical attackers to extract firmware via the debug interface and exception handling.
Severity CVSS v4.0: Pending analysis
Last modification:
10/09/2020

CVE-2020-15687

Publication date:
31/08/2020
Missing access control restrictions in the Hypervisor component of the ACRN Project (v2.0 and v1.6.1) allow a malicious entity, with root access in the Service VM userspace, to abuse the PCIe assign/de-assign Hypercalls via crafted ioctls and payloads. This attack results in a corrupt state and Denial of Service (DoS) for previously assigned PCIe devices to the Service VM at runtime.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2020

CVE-2020-13471

Publication date:
31/08/2020
Apex Microelectronics APM32F103 devices allow physical attackers to execute arbitrary code via a power glitch and a specific flash patch/breakpoint unit configuration.
Severity CVSS v4.0: Pending analysis
Last modification:
09/09/2020

CVE-2020-13466

Publication date:
31/08/2020
STMicroelectronics STM32F103 devices through 2020-05-20 allow physical attackers to execute arbitrary code via a power glitch and a specific flash patch/breakpoint unit configuration.
Severity CVSS v4.0: Pending analysis
Last modification:
09/09/2020

CVE-2020-13467

Publication date:
31/08/2020
The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attackers to extract firmware via the debug interface and exception handling.
Severity CVSS v4.0: Pending analysis
Last modification:
09/09/2020

CVE-2020-13469

Publication date:
31/08/2020
The flash memory readout protection in Gigadevice GD32VF103 devices allows physical attackers to extract firmware via the debug interface by utilizing the CPU.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2020

CVE-2020-17465

Publication date:
31/08/2020
Dashboards and progressiveProfileForms in ForgeRock Identity Manager before 7.0.0 are vulnerable to stored XSS. The vulnerability affects versions 6.5.0.4, 6.0.0.6.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2020