Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-39299

Publication date:
16/02/2022
Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
07/03/2022

CVE-2021-39297

Publication date:
16/02/2022
Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
07/03/2022

CVE-2021-39300

Publication date:
16/02/2022
Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
07/03/2022

CVE-2021-21958

Publication date:
16/02/2022
A heap-based buffer overflow vulnerability exists in the Hword HwordApp.dll functionality of Hancom Office 2020 11.0.0.2353. A specially-crafted malformed file can lead to memory corruption and potential arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
12/05/2022

CVE-2021-21966

Publication date:
16/02/2022
An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 SimpleLink Solution NWP 2.9.0.0. A specially-crafted HTTP request can lead to an uninitialized read. An attacker can send an HTTP request to trigger this vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2022

CVE-2020-6922

Publication date:
16/02/2022
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2022

CVE-2020-6921

Publication date:
16/02/2022
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2022

CVE-2020-6920

Publication date:
16/02/2022
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2022

CVE-2020-6919

Publication date:
16/02/2022
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2022

CVE-2020-6918

Publication date:
16/02/2022
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2022

CVE-2021-39298

Publication date:
16/02/2022
A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security mechanisms provided in the UEFI firmware.
Severity CVSS v4.0: Pending analysis
Last modification:
24/02/2026

CVE-2019-4352

Publication date:
16/02/2022
IBM Maximo Anywhere 7.6.4.0 applications could allow obfuscation of the application source code. IBM X-Force ID: 161494.
Severity CVSS v4.0: Pending analysis
Last modification:
23/02/2022