Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-33330

Publication date:
03/08/2021
Liferay Portal 7.2.0 through 7.3.2, and Liferay DXP 7.2 before fix pack 9, allows access to Cross-origin resource sharing (CORS) protected resources if the user is only authenticated using the portal session authentication, which allows remote attackers to obtain sensitive information including the targeted user’s email address and current CSRF token.
Severity CVSS v4.0: Pending analysis
Last modification:
13/05/2025

CVE-2021-36623

Publication date:
03/08/2021
Arbitrary File Upload in Sourcecodester Phone Shop Sales Management System 1.0 enables RCE.
Severity CVSS v4.0: Pending analysis
Last modification:
06/11/2021

CVE-2021-36654

Publication date:
03/08/2021
CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while updating the theme.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2021

CVE-2021-36622

Publication date:
03/08/2021
Sourcecodester Online Covid Vaccination Scheduler System 1.0 is affected vulnerable to Arbitrary File Upload. The admin panel has an upload function of profile photo accessible at http://localhost/scheduler/admin/?page=user. An attacker could upload a malicious file such as shell.php with the Content-Type: image/png. Then, the attacker have to visit the uploaded profile photo to access the shell.
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2021

CVE-2021-32018

Publication date:
03/08/2021
An issue was discovered in JUMP AMS 3.6.0.04.009-2487. The JUMP SOAP API was vulnerable to arbitrary file reading due to an improper limitation of file loading on the server filesystem, aka directory traversal.
Severity CVSS v4.0: Pending analysis
Last modification:
30/05/2025

CVE-2021-22420

Publication date:
03/08/2021
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust of the application trustlist mechanism is missing..
Severity CVSS v4.0: Pending analysis
Last modification:
03/05/2022

CVE-2021-32016

Publication date:
03/08/2021
An issue was discovered in JUMP AMS 3.6.0.04.009-2487. A JUMP SOAP endpoint permitted the writing of arbitrary files to a user-controlled location on the remote filesystem (with user-controlled content) via directory traversal, potentially leading to remote code and command execution.
Severity CVSS v4.0: Pending analysis
Last modification:
30/05/2025

CVE-2021-22425

Publication date:
03/08/2021
A component of the HarmonyOS has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevating Privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2021

CVE-2021-22423

Publication date:
03/08/2021
A component of the HarmonyOS has a Out-of-bounds Write Vulnerability. Local attackers may exploit this vulnerability to cause integer overflow.
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2021

CVE-2021-27942

Publication date:
03/08/2021
Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs allow a threat actor to execute arbitrary code from a USB drive via the Smart Cast functionality, because files on the USB drive are effectively under the web root and can be executed.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2021

CVE-2021-22424

Publication date:
03/08/2021
A component of the HarmonyOS has a Kernel Memory Leakage Vulnerability. Local attackers may exploit this vulnerability to cause Kernel Denial of Service.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2021

CVE-2021-22417

Publication date:
03/08/2021
A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel Memory Leakage.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2021