Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-36217

Publication date:
26/01/2021
An issue was discovered in the may_queue crate through 2020-11-10 for Rust. Because Queue does not have bounds on its Send trait or Sync trait, memory corruption can occur.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-36220

Publication date:
26/01/2021
An issue was discovered in the va-ts crate before 0.0.4 for Rust. Because Demuxer omits a required T: Send bound, a data race and memory corruption can occur.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-36200

Publication date:
26/01/2021
TinyCheck before commits 9fd360d and ea53de8 allowed an authenticated attacker to send an HTTP GET request to the crafted URLs.
Severity CVSS v4.0: Pending analysis
Last modification:
02/02/2021

CVE-2020-36205

Publication date:
26/01/2021
An issue was discovered in the xcb crate through 2020-12-10 for Rust. base::Error does not have soundness. Because of the public ptr field, a use-after-free or double-free can occur.
Severity CVSS v4.0: Pending analysis
Last modification:
03/02/2021

CVE-2020-36204

Publication date:
26/01/2021
An issue was discovered in the im crate through 2020-11-09 for Rust. Because TreeFocus does not have bounds on its Send trait or Sync trait, a data race can occur.
Severity CVSS v4.0: Pending analysis
Last modification:
03/02/2021

CVE-2020-36209

Publication date:
26/01/2021
An issue was discovered in the late-static crate before 0.4.0 for Rust. Because Sync is implemented for LateStatic with T: Send, a data race can occur.
Severity CVSS v4.0: Pending analysis
Last modification:
03/02/2021

CVE-2020-36011

Publication date:
26/01/2021
A cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote attacker to inject arbitrary code via the Name, Guardian Name, Email, Address, Remarks, or Any Known Allergies field.
Severity CVSS v4.0: Pending analysis
Last modification:
01/02/2021

CVE-2020-35853

Publication date:
26/01/2021
4images Image Gallery Management System 1.7.11 is affected by cross-site scripting (XSS) in the Image URL. This vulnerability can result in an attacker to inject the XSS payload into the IMAGE URL. Each time a user visits that URL, the XSS triggers and the attacker can be able to steal the cookie according to the crafted payload.
Severity CVSS v4.0: Pending analysis
Last modification:
01/02/2021

CVE-2020-36202

Publication date:
26/01/2021
An issue was discovered in the async-h1 crate before 2.3.0 for Rust. Request smuggling can occur when used behind a reverse proxy.
Severity CVSS v4.0: Pending analysis
Last modification:
10/02/2021

CVE-2020-35854

Publication date:
26/01/2021
Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
01/02/2021

CVE-2020-36199

Publication date:
26/01/2021
TinyCheck before commits 9fd360d and ea53de8 was vulnerable to command injection due to insufficient checks of input parameters in several places.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-36201

Publication date:
26/01/2021
An issue was discovered in certain Xerox WorkCentre products. They do not properly encrypt passwords. This affects 3655, 3655i, 58XX, 58XXi 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021