Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-3285

Publication date:
26/01/2021
jxbrowser in TI Code Composer Studio IDE 8.x through 10.x before 10.1.1 does not verify X.509 certificates for HTTPS.
Severity CVSS v4.0: Pending analysis
Last modification:
03/02/2021

CVE-2021-3304

Publication date:
26/01/2021
Sagemcom F@ST 3686 v2 3.495 devices have a buffer overflow via a long sessionKey to the goform/login URI.
Severity CVSS v4.0: Pending analysis
Last modification:
03/02/2021

CVE-2021-3278

Publication date:
26/01/2021
Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection . Using this vulnerability, an attacker can bypass the login page.
Severity CVSS v4.0: Pending analysis
Last modification:
26/04/2022

CVE-2021-3286

Publication date:
26/01/2021
SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variation of the payload may be used. NOTE: this issue exists because of an incomplete fix for CVE-2020-35545.
Severity CVSS v4.0: Pending analysis
Last modification:
30/01/2021

CVE-2021-3297

Publication date:
26/01/2021
On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.
Severity CVSS v4.0: Pending analysis
Last modification:
25/11/2025

CVE-2021-3193

Publication date:
26/01/2021
Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated attacker to execute remote code as the apache user.
Severity CVSS v4.0: Pending analysis
Last modification:
03/02/2021

CVE-2021-3188

Publication date:
26/01/2021
phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.
Severity CVSS v4.0: Pending analysis
Last modification:
03/02/2021

CVE-2021-3223

Publication date:
26/01/2021
Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.
Severity CVSS v4.0: Pending analysis
Last modification:
28/01/2021

CVE-2021-3195

Publication date:
26/01/2021
bitcoind in Bitcoin Core through 0.21.0 can create a new file in an arbitrary directory (e.g., outside the ~/.bitcoin directory) via a dumpwallet RPC call. NOTE: this reportedly does not violate the security model of Bitcoin Core, but can violate the security model of a fork that has implemented dumpwallet restrictions
Severity CVSS v4.0: Pending analysis
Last modification:
03/08/2024

CVE-2021-3199

Publication date:
26/01/2021
Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2022

CVE-2021-3190

Publication date:
26/01/2021
The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag.
Severity CVSS v4.0: Pending analysis
Last modification:
29/04/2022

CVE-2021-3186

Publication date:
26/01/2021
A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_multi allows remote attackers to inject arbitrary web script or HTML via the Wifi Name parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
07/07/2025