Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-20799

Publication date:
18/05/2020
In Cherokee through 1.2.104, multiple memory corruption errors may be used by a remote attacker to destabilize the work of a server.
Severity CVSS v4.0: Pending analysis
Last modification:
28/04/2022

CVE-2019-20800

Publication date:
18/05/2020
In Cherokee through 1.2.104, remote attackers can trigger an out-of-bounds write in cherokee_handler_cgi_add_env_pair in handler_cgi.c by sending many request headers, as demonstrated by a GET request with many "Host: 127.0.0.1" headers.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2022

CVE-2019-20801

Publication date:
18/05/2020
An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin requests from any domain, and the WebSocket server lacks authorization control. Any web site can execute JavaScript code (that accesses a user's data) via cross-origin requests.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-4345

Publication date:
17/05/2020
IBM i 7.2, 7.3, and 7.4 users running complex SQL statements under a specific set of circumstances may allow a local user to obtain sensitive information that they should not have access to. IBM X-Force ID: 178318.
Severity CVSS v4.0: Pending analysis
Last modification:
18/05/2020

CVE-2020-13126

Publication date:
17/05/2020
An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary executable files to achieve remote code execution. NOTE: the free Elementor plugin is unaffected.
Severity CVSS v4.0: Pending analysis
Last modification:
25/08/2020

CVE-2020-13125

Publication date:
17/05/2020
An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-13121

Publication date:
16/05/2020
Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.
Severity CVSS v4.0: Pending analysis
Last modification:
18/05/2020

CVE-2020-13118

Publication date:
16/05/2020
An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the parameter community.
Severity CVSS v4.0: Pending analysis
Last modification:
19/05/2020

CVE-2020-13111

Publication date:
16/05/2020
NaviServer 4.99.4 to 4.99.19 allows denial of service due to the nsd/driver.c ChunkedDecode function not properly validating the length of a chunk. A remote attacker can craft a chunked-transfer request that will result in a negative value being passed to memmove via the size parameter, causing the process to crash.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-13110

Publication date:
16/05/2020
The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of malicious DLLs through use of the kerberos_sspi LoadLibrary() method, because of a DLL path search.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-13109

Publication date:
16/05/2020
Morita Shogi 64 through 2020-05-02 for Nintendo 64 devices allows remote attackers to execute arbitrary code via crafted packet data to the built-in modem because 0x800b3e94 (aka the IF subcommand to top-level command 7) has a stack-based buffer overflow.
Severity CVSS v4.0: Pending analysis
Last modification:
20/05/2020

CVE-2020-13093

Publication date:
15/05/2020
iSpyConnect.com Agent DVR before 2.7.1.0 allows directory traversal.
Severity CVSS v4.0: Pending analysis
Last modification:
15/05/2020