Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-26119

Publication date:
22/02/2021
Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.
Severity CVSS v4.0: Pending analysis
Last modification:
14/10/2022

CVE-2021-3149

Publication date:
22/02/2021
On Netshield NANO 25 10.2.18 devices, /usr/local/webmin/System/manual_ping.cgi allows OS command injection (after authentication by the attacker) because the system C library function is used unsafely.
Severity CVSS v4.0: Pending analysis
Last modification:
25/07/2022

CVE-2021-27513

Publication date:
22/02/2021
The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre userside."
Severity CVSS v4.0: Pending analysis
Last modification:
26/02/2021

CVE-2021-27514

Publication date:
22/02/2021
EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication bypass (such as in CVE-2021-27513 exploitation).
Severity CVSS v4.0: Pending analysis
Last modification:
26/02/2021

CVE-2021-27515

Publication date:
22/02/2021
url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
Severity CVSS v4.0: Pending analysis
Last modification:
23/02/2023

CVE-2021-27516

Publication date:
22/02/2021
URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
Severity CVSS v4.0: Pending analysis
Last modification:
29/11/2022

CVE-2021-26716

Publication date:
21/02/2021
Modules/input/Views/schedule.php in Emoncms through 10.2.7 allows XSS via the node parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
26/02/2021

CVE-2021-26544

Publication date:
20/02/2021
Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw to access logs and results of other users' sessions and run jobs with their privileges. This issue is fixed in Livy 0.7.1-incubating.
Severity CVSS v4.0: Pending analysis
Last modification:
26/02/2021

CVE-2020-28248

Publication date:
20/02/2021
An integer overflow in the PngImg::InitStorage_() function of png-img before 3.1.0 leads to an under-allocation of heap memory and subsequently an exploitable heap-based buffer overflow when loading a crafted PNG file.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-24392

Publication date:
19/02/2021
In voloko twitter-stream 0.1.10, missing TLS hostname validation allows an attacker to perform a man-in-the-middle attack against users of the library (because eventmachine is misused).
Severity CVSS v4.0: Pending analysis
Last modification:
25/02/2021

CVE-2020-12873

Publication date:
19/02/2021
An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a webscript) may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running Alfresco.
Severity CVSS v4.0: Pending analysis
Last modification:
25/02/2021

CVE-2020-24617

Publication date:
19/02/2021
Mailtrain through 1.24.1 allows SQL Injection in statsClickedSubscribersByColumn in lib/models/campaigns.js via /campaigns/clicked/ajax because variable column names are not properly escaped.
Severity CVSS v4.0: Pending analysis
Last modification:
25/02/2021