Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-32487

Publication date:
09/09/2021
In modem 2G RRM, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00500736; Issue ID: ALPS04938456.
Severity CVSS v4.0: Pending analysis
Last modification:
21/09/2021

CVE-2021-32484

Publication date:
09/09/2021
In modem 2G RRM, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00500621; Issue ID: ALPS04964917.
Severity CVSS v4.0: Pending analysis
Last modification:
21/09/2021

CVE-2021-38721

Publication date:
09/09/2021
FUEL CMS 1.5.0 login.php contains a cross-site request forgery (CSRF) vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
20/09/2021

CVE-2021-38723

Publication date:
09/09/2021
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/pages/items
Severity CVSS v4.0: Pending analysis
Last modification:
20/09/2021

CVE-2021-38725

Publication date:
09/09/2021
Fuel CMS 1.5.0 has a brute force vulnerability in fuel/modules/fuel/controllers/Login.php
Severity CVSS v4.0: Pending analysis
Last modification:
20/09/2021

CVE-2021-38540

Publication date:
09/09/2021
The variable import endpoint was not protected by authentication in Airflow >=2.0.0, =2.0.0,
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-19515

Publication date:
09/09/2021
qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php.
Severity CVSS v4.0: Pending analysis
Last modification:
20/09/2021

CVE-2021-22239

Publication date:
09/09/2021
An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later.
Severity CVSS v4.0: Pending analysis
Last modification:
21/09/2021

CVE-2020-19144

Publication date:
09/09/2021
Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the 'in _TIFFmemcpy' funtion in the component 'tif_unix.c'.
Severity CVSS v4.0: Pending analysis
Last modification:
02/12/2021

CVE-2020-19143

Publication date:
09/09/2021
Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "TIFFVGetField" funtion in the component 'libtiff/tif_dir.c'.
Severity CVSS v4.0: Pending analysis
Last modification:
30/11/2021

CVE-2021-3761

Publication date:
09/09/2021
Any CA issuer in the RPKI can trick OctoRPKI prior to 1.3.0 into emitting an invalid VRP "MaxLength" value, causing RTR sessions to terminate. An attacker can use this to disable RPKI Origin Validation in a victim network (for example AS 13335 - Cloudflare) prior to launching a BGP hijack which during normal operations would be rejected as "RPKI invalid". Additionally, in certain deployments RTR session flapping in and of itself also could cause BGP routing churn, causing availability issues.
Severity CVSS v4.0: Pending analysis
Last modification:
04/04/2022

CVE-2021-37101

Publication date:
09/09/2021
There is an improper authorization vulnerability in AIS-BW50-00 9.0.6.2(H100SP10C00) and 9.0.6.2(H100SP15C00). Due to improper authorization mangement, an attakcer can exploit this vulnerability by physical accessing the device and implant malicious code. Successfully exploit could leads to arbitrary code execution in the target device.
Severity CVSS v4.0: Pending analysis
Last modification:
03/05/2022