Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-20511

Publication date:
18/03/2020
ERPNext 11.1.47 allows blog?blog_category= Frame Injection.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-20529

Publication date:
18/03/2020
In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (no authentication is required to access; having a link is sufficient) instead of private files.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2019-20512

Publication date:
18/03/2020
Open edX Ironwood.1 allows support/certificates?course_id= reflected XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
19/03/2020

CVE-2019-3762

Publication date:
18/03/2020
Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by obtaining a CA signed certificate from Data Protection Central to impersonate a valid system to compromise the integrity of data.
Severity CVSS v4.0: Pending analysis
Last modification:
27/03/2020

CVE-2019-12921

Publication date:
18/03/2020
In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.
Severity CVSS v4.0: Pending analysis
Last modification:
31/03/2022

CVE-2019-18582

Publication date:
18/03/2020
Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server-side template injection vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may potentially exploit this vulnerability to inject malicious report generation scripts in the server. This may lead to OS command execution as the regular user runs the DPA service on the affected system.
Severity CVSS v4.0: Pending analysis
Last modification:
24/03/2020

CVE-2019-18581

Publication date:
18/03/2020
Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server missing authorization vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may potentially exploit this vulnerability to alter the application’s allowable list of OS commands. This may lead to arbitrary OS command execution as the regular user runs the DPA service on the affected system.
Severity CVSS v4.0: Pending analysis
Last modification:
24/03/2020

CVE-2019-12132

Publication date:
18/03/2020
An issue was discovered in ONAP SDNC before Dublin. By executing sla/dgUpload with a crafted filename parameter, an unauthenticated attacker can execute an arbitrary command. All SDC setups that include admportal are affected.
Severity CVSS v4.0: Pending analysis
Last modification:
20/03/2020

CVE-2019-12769

Publication date:
18/03/2020
SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forgery in the file upload functionality via ?Command=Upload with the Dir and File parameters.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-12370

Publication date:
18/03/2020
The Spark application through 2.0.2 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
Severity CVSS v4.0: Pending analysis
Last modification:
19/03/2020

CVE-2019-12365

Publication date:
18/03/2020
The Newton application through 10.0.23 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
Severity CVSS v4.0: Pending analysis
Last modification:
19/03/2020

CVE-2019-12366

Publication date:
18/03/2020
The Nine application through 4.5.3a for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
Severity CVSS v4.0: Pending analysis
Last modification:
19/03/2020