Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-34174

Publication date:
14/07/2021
A vulnerability exists in Broadcom BCM4352 and BCM43684 chips. Any wireless router using BCM4352 and BCM43684 will be affected, such as ASUS AX6100. An attacker may cause a Denial of Service (DoS) to any device connected to BCM4352 or BCM43684 routers via an association or reassociation frame.
Severity CVSS v4.0: Pending analysis
Last modification:
26/07/2021

CVE-2020-18151

Publication date:
14/07/2021
Cross Site Request Forgery (CSRF) vulnerability in ThinkCMF v5.1.0, which can add an admin account.
Severity CVSS v4.0: Pending analysis
Last modification:
28/10/2022

CVE-2021-34518

Publication date:
14/07/2021
Microsoft Excel Remote Code Execution Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
28/12/2023

CVE-2021-34514

Publication date:
14/07/2021
Windows Kernel Elevation of Privilege Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
28/12/2023

CVE-2021-34512

Publication date:
14/07/2021
Storage Spaces Controller Elevation of Privilege Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
28/12/2023

CVE-2021-34520

Publication date:
14/07/2021
Microsoft SharePoint Server Remote Code Execution Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
28/12/2023

CVE-2021-34517

Publication date:
14/07/2021
Microsoft SharePoint Server Spoofing Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
28/12/2023

CVE-2021-34519

Publication date:
14/07/2021
Microsoft SharePoint Server Information Disclosure Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
28/12/2023

CVE-2021-34521

Publication date:
14/07/2021
Raw Image Extension Remote Code Execution Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
28/12/2023

CVE-2021-34525

Publication date:
14/07/2021
Windows DNS Server Remote Code Execution Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
28/12/2023

CVE-2021-34528

Publication date:
14/07/2021
Visual Studio Code Remote Code Execution Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
28/12/2023

CVE-2021-34529

Publication date:
14/07/2021
Visual Studio Code Remote Code Execution Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
28/12/2023