Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-36455

Publication date:
06/08/2021
SQL Injection vulnerability in Naviwebs Navigate CMS 2.9 via the quicksearch parameter in \lib\packages\comments\comments.php.
Severity CVSS v4.0: Pending analysis
Last modification:
13/08/2021

CVE-2021-36454

Publication date:
06/08/2021
Cross Site Scripting (XSS) vulnerability in Naviwebs Navigate Cms 2.9 via the navigate-quickse parameter to 1) backups\backups.php, 2) blocks\blocks.php, 3) brands\brands.php, 4) comments\comments.php, 5) coupons\coupons.php, 6) feeds\feeds.php, 7) functions\functions.php, 8) items\items.php, 9) menus\menus.php, 10) orders\orders.php, 11) payment_methods\payment_methods.php, 12) products\products.php, 13) profiles\profiles.php, 14) shipping_methods\shipping_methods.php, 15) templates\templates.php, 16) users\users.php, 17) webdictionary\webdictionary.php, 18) websites\websites.php, and 19) webusers\webusers.php because the initial_url function is built in these files.
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2021

CVE-2021-26998

Publication date:
06/08/2021
NetApp Cloud Manager versions prior to 3.9.9 log sensitive information that is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using on-prem connectors with auto-upgrade disabled are advised to upgrade to a fixed version.
Severity CVSS v4.0: Pending analysis
Last modification:
28/06/2022

CVE-2021-26999

Publication date:
06/08/2021
NetApp Cloud Manager versions prior to 3.9.9 log sensitive information when an Active Directory connection fails. The logged information is available only to authenticated users. Customers with auto-upgrade enabled should already be on a fixed version while customers using on-prem connectors with auto-upgrade disabled are advised to upgrade to a fixed version.
Severity CVSS v4.0: Pending analysis
Last modification:
28/06/2022

CVE-2021-26606

Publication date:
06/08/2021
A vulnerability in PKI Security Solution of Dream Security could allow arbitrary command execution. This vulnerability is due to insufficient validation of the authorization certificate. An attacker could exploit this vulnerability by sending a crafted HTTP request an affected program. A successful exploit could allow the attacker to remotely execute arbitrary code on a target system.
Severity CVSS v4.0: Pending analysis
Last modification:
13/08/2021

CVE-2021-38136

Publication date:
06/08/2021
Corero SecureWatch Managed Services 9.7.2.0020 is affected by a Path Traversal vulnerability via the snap_file parameter in the /it-IT/splunkd/__raw/services/get_snapshot HTTP API endpoint. A ‘low privileged’ attacker can read any file on the target host.
Severity CVSS v4.0: Pending analysis
Last modification:
13/08/2021

CVE-2021-38137

Publication date:
06/08/2021
Corero SecureWatch Managed Services 9.7.2.0020 does not correctly check swa-monitor and cns-monitor user’s privileges, allowing a user to perform actions not belonging to his role.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2022

CVE-2021-37554

Publication date:
06/08/2021
In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.
Severity CVSS v4.0: Pending analysis
Last modification:
28/06/2022

CVE-2021-37547

Publication date:
06/08/2021
In JetBrains TeamCity before 2020.2.4, insufficient checks during file uploading were made.
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2021

CVE-2021-37548

Publication date:
06/08/2021
In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS.
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2021

CVE-2021-37549

Publication date:
06/08/2021
In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient.
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2021

CVE-2021-37550

Publication date:
06/08/2021
In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used.
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2021