Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-29363

Publication date:
28/09/2021
A buffer overflow vulnerability in FORMATS!ReadRAS_W+0xa74 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.0xa74
Severity CVSS v4.0: Pending analysis
Last modification:
05/10/2021

CVE-2021-29362

Publication date:
28/09/2021
A buffer overflow vulnerability in FORMATS!ReadRAS_W+0xa30 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.
Severity CVSS v4.0: Pending analysis
Last modification:
05/10/2021

CVE-2021-29367

Publication date:
28/09/2021
A buffer overflow vulnerability in WPG+0x1dda of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted WPG file.
Severity CVSS v4.0: Pending analysis
Last modification:
05/10/2021

CVE-2021-29366

Publication date:
28/09/2021
A buffer overflow vulnerability in FORMATS!GetPlugInInfo+0x2de9 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.
Severity CVSS v4.0: Pending analysis
Last modification:
06/10/2021

CVE-2021-29364

Publication date:
28/09/2021
A buffer overflow vulnerability in Formats!ReadRAS_W+0x1001 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.
Severity CVSS v4.0: Pending analysis
Last modification:
06/10/2021

CVE-2021-29365

Publication date:
28/09/2021
Irfanview 4.57 is affected by an infinite loop when processing a crafted BMP file in the EFFECTS!AutoCrop_W component. This can cause a denial of service (DOS).
Severity CVSS v4.0: Pending analysis
Last modification:
06/10/2021

CVE-2021-41104

Publication date:
28/09/2021
ESPHome is a system to control the ESP8266/ESP32. Anyone with web_server enabled and HTTP basic auth configured on version 2021.9.1 or older is vulnerable to an issue in which `web_server` allows over-the-air (OTA) updates without checking user defined basic auth username & password. This issue is patched in version 2021.9.2. As a workaround, one may disable or remove `web_server`.
Severity CVSS v4.0: Pending analysis
Last modification:
07/10/2021

CVE-2021-29358

Publication date:
28/09/2021
A buffer overflow vulnerability in FORMATS!ReadPVR_W+0xfa of Irfanview 4.57 allows attackers to cause a denial of service (DOS) via a crafted PVR file.
Severity CVSS v4.0: Pending analysis
Last modification:
05/10/2021

CVE-2021-37106

Publication date:
28/09/2021
There is a command injection vulnerability in CMA service module of FusionCompute 6.3.0, 6.3.1, 6.5.0 and 8.0.0 when processing the default certificate file. The software constructs part of a command using external special input from users, but the software does not sufficiently validate the user input. Successful exploit could allow the attacker to inject certain commands to the system.
Severity CVSS v4.0: Pending analysis
Last modification:
03/05/2022

CVE-2021-37105

Publication date:
28/09/2021
There is an improper file upload control vulnerability in FusionCompute 6.5.0, 6.5.1 and 8.0.0. Due to the improper verification of file to be uploaded and does not strictly restrict the file access path, attackers may upload malicious files to the device, resulting in the service abnormal.
Severity CVSS v4.0: Pending analysis
Last modification:
06/10/2021

CVE-2021-37104

Publication date:
28/09/2021
There is a server-side request forgery vulnerability in HUAWEI P40 versions 10.1.0.118(C00E116R3P3). This vulnerability is due to insufficient validation of parameters while dealing with some messages. A successful exploit could allow the attacker to gain access to certain resource which the attacker are supposed not to do.
Severity CVSS v4.0: Pending analysis
Last modification:
06/10/2021

CVE-2021-22535

Publication date:
28/09/2021
Unauthorized information security disclosure vulnerability on Micro Focus Directory and Resource Administrator (DRA) product, affecting all DRA versions prior to 10.1 Patch 1. The vulnerability could lead to unauthorized information disclosure.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023