Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-14837

Publication date:
07/01/2020
A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name of a client can reset password and then log in. For example, for client name 'test' the email address will be 'service-account-test@placeholder.org'.
Severity CVSS v4.0: Pending analysis
Last modification:
15/01/2020

CVE-2019-14843

Publication date:
07/01/2020
A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized information and possibly conduct further attacks. Versions shipped with Red Hat Jboss EAP 7 and Red Hat SSO 7 are vulnerable to this issue.
Severity CVSS v4.0: Pending analysis
Last modification:
15/01/2020

CVE-2019-14879

Publication date:
07/01/2020
A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable).
Severity CVSS v4.0: Pending analysis
Last modification:
31/03/2020

CVE-2019-14854

Publication date:
07/01/2020
OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.
Severity CVSS v4.0: Pending analysis
Last modification:
12/02/2023

CVE-2019-14866

Publication date:
07/01/2020
In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.
Severity CVSS v4.0: Pending analysis
Last modification:
04/06/2023

CVE-2013-5658

Publication date:
07/01/2020
AultWare pwStore 2010.8.30.0 has XSS
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2020

CVE-2013-5657

Publication date:
07/01/2020
AultWare pwStore 2010.8.30.0 has DoS via an empty HTTP request
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2020

CVE-2013-5638

Publication date:
07/01/2020
Transcend WiFiSD 1.8 has persistent XSS
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2020

CVE-2013-5637

Publication date:
07/01/2020
PQI AirCard has persistent XSS
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2020

CVE-2013-5656

Publication date:
07/01/2020
FuzeZip 1.0.0.131625 has a Local Buffer Overflow vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2020

CVE-2019-14834

Publication date:
07/01/2020
A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHCP response creation.
Severity CVSS v4.0: Pending analysis
Last modification:
12/02/2023

CVE-2020-5393

Publication date:
07/01/2020
In Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2020