Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2013-2011

Publication date:
26/12/2019
WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code. This issue exists because of an incomplete fix for CVE-2013-2009.
Severity CVSS v4.0: Pending analysis
Last modification:
02/01/2020

CVE-2019-19389

Publication date:
26/12/2019
JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2015-5290

Publication date:
26/12/2019
A Denial of Service vulnerability exists in ircd-ratbox 3.0.9 in the MONITOR Command Handler.
Severity CVSS v4.0: Pending analysis
Last modification:
19/01/2023

CVE-2012-4420

Publication date:
26/12/2019
An information disclosure flaw was found in the way the Java Virtual Machine (JVM) implementation of Java SE 7 as provided by OpenJDK 7 incorrectly initialized integer arrays after memory allocation (in certain circumstances they had nonzero elements right after the allocation). A remote attacker could use this flaw to obtain potentially sensitive information.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2012-3462

Publication date:
26/12/2019
A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing to be ignored in the event that the access-provider is also handling the setup of the user's SELinux user context.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2012-2736

Publication date:
26/12/2019
In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2019-5275

Publication date:
26/12/2019
USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 implementation in the affected products which can result in a heap buffer overflow when decoding a certificate, an attacker may exploit the vulnerability by a malicious certificate to perform a denial of service attack on the affected products.
Severity CVSS v4.0: Pending analysis
Last modification:
31/12/2019

CVE-2019-5274

Publication date:
26/12/2019
USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 implementation in the affected products which can result in an infinite loop, an attacker may exploit the vulnerability via a malicious certificate to perform a denial of service attack on the affected products.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2019-19398

Publication date:
26/12/2019
M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability. Due to the input validation logic is incorrect, an attacker can exploit this vulnerability to modify the memory of the device by doing a series of operations. Successful exploit may lead to malicious code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
02/01/2020

CVE-2019-5272

Publication date:
26/12/2019
USG9500 with versions of V500R001C30;V500R001C60 have a missing integrity checking vulnerability. The software of the affected products does not check the integrity which may allow an attacker with high privilege to make malicious modifications without detection.
Severity CVSS v4.0: Pending analysis
Last modification:
31/12/2019

CVE-2019-5273

Publication date:
26/12/2019
USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 implementation in the affected products which can result in a large heap buffer overrun error, an attacker may exploit the vulnerability by a malicious certificate, resulting a denial of service on the affected products.
Severity CVSS v4.0: Pending analysis
Last modification:
31/12/2019

CVE-2011-1474

Publication date:
26/12/2019
A locally locally exploitable DOS vulnerability was found in pax-linux versions 2.6.32.33-test79.patch, 2.6.38-test3.patch, and 2.6.37.4-test14.patch. A bad bounds check in arch_get_unmapped_area_topdown triggered by programs doing an mmap after a MAP_GROWSDOWN mmap will create an infinite loop condition without releasing the VM semaphore eventually leading to a system crash.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024