Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-10691

Publication date:
30/04/2020
An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-6010

Publication date:
30/04/2020
LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
Severity CVSS v4.0: Pending analysis
Last modification:
19/07/2021

CVE-2020-6579

Publication date:
30/04/2020
Cross-site scripting (XSS) vulnerability in mailhive/cloudbeez/cloudloader.php and mailhive/cloudbeez/cloudloader_core.php in the MailBeez plugin for ZenCart before 3.9.22 allows remote attackers to inject arbitrary web script or HTML via the cloudloader_mode parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
01/05/2020

CVE-2019-19219

Publication date:
30/04/2020
BMC Control-M/Agent 7.0.00.000 allows Arbitrary File Download.
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2020

CVE-2019-19217

Publication date:
30/04/2020
BMC Control-M/Agent 7.0.00.000 allows OS Command Injection.
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2020

CVE-2020-12101

Publication date:
30/04/2020
The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by manipulating an id field in the POST request for altering an address.
Severity CVSS v4.0: Pending analysis
Last modification:
29/04/2024

CVE-2019-19215

Publication date:
30/04/2020
A buffer overflow vulnerability in BMC Control-M/Agent 7.0.00.000 when the On-Do action destination is Mail and the Control-M/Agent is configured to send the email, allows remote attackers to have unspecified impact via vectors related to the configured IP address or SMTP server.
Severity CVSS v4.0: Pending analysis
Last modification:
26/05/2020

CVE-2019-19216

Publication date:
30/04/2020
BMC Control-M/Agent 7.0.00.000 has an Insecure File Copy.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2019-19218

Publication date:
30/04/2020
BMC Control-M/Agent 7.0.00.000 has Insecure Password Storage.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2019-19220

Publication date:
30/04/2020
BMC Control-M/Agent 7.0.00.000 allows OS Command Injection (issue 2 of 2).
Severity CVSS v4.0: Pending analysis
Last modification:
04/05/2020

CVE-2020-9387

Publication date:
30/04/2020
In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' is turned on.
Severity CVSS v4.0: Pending analysis
Last modification:
12/05/2020

CVE-2020-12283

Publication date:
30/04/2020
Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/redirect.go, such as for the //foo//example.com substring.
Severity CVSS v4.0: Pending analysis
Last modification:
04/03/2021