Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2013-6460

Publication date:
05/11/2019
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
Severity CVSS v4.0: Pending analysis
Last modification:
15/07/2021

CVE-2013-6461

Publication date:
05/11/2019
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
Severity CVSS v4.0: Pending analysis
Last modification:
15/07/2021

CVE-2019-17221

Publication date:
05/11/2019
PhantomJS through 2.1.1 has an arbitrary file read vulnerability, as demonstrated by an XMLHttpRequest for a file:// URI. The vulnerability exists in the page.open() function of the webpage module, which loads a specified URL and calls a given callback. An attacker can supply a specially crafted HTML file, as user input, that allows reading arbitrary files on the filesystem. For example, if page.render() is the function callback, this generates a PDF or an image of the targeted file. NOTE: this product is no longer developed.
Severity CVSS v4.0: Pending analysis
Last modification:
08/11/2019

CVE-2013-6365

Publication date:
05/11/2019
Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions
Severity CVSS v4.0: Pending analysis
Last modification:
18/08/2020

CVE-2016-1000002

Publication date:
05/11/2019
gdm3 3.14.2 and possibly later has an information leak before screen lock
Severity CVSS v4.0: Pending analysis
Last modification:
18/08/2020

CVE-2013-6364

Publication date:
05/11/2019
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
Severity CVSS v4.0: Pending analysis
Last modification:
18/08/2020

CVE-2013-4110

Publication date:
05/11/2019
Cryptocat has an Unspecified Chat Participant User List Disclosure
Severity CVSS v4.0: Pending analysis
Last modification:
05/11/2019

CVE-2013-4107

Publication date:
05/11/2019
Cryptocat before 2.0.22: cryptocat.js handlePresence() has cross site scripting
Severity CVSS v4.0: Pending analysis
Last modification:
05/11/2019

CVE-2019-10223

Publication date:
05/11/2019
A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that enabled annotations to be exposed as metrics. By default, the kube-state-metrics metrics only expose metadata about Secrets. However, a combination of the default `kubectl` behavior and this new feature can cause the entire secret content to end up in metric labels thus inadvertently exposing the secret content in metrics. This feature has been reverted and released as the v1.7.2 release. If you are running the v1.7.0 or v1.7.1 release, please upgrade to the v1.7.2 release as soon as possible.
Severity CVSS v4.0: Pending analysis
Last modification:
29/11/2019

CVE-2019-3685

Publication date:
05/11/2019
Open Build Service before version 0.165.4 diddn't validate TLS certificates for HTTPS connections with the osc client binary
Severity CVSS v4.0: Pending analysis
Last modification:
08/11/2019

CVE-2010-3668

Publication date:
04/11/2019
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Header Injection in the secure download feature jumpurl.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2010-3669

Publication date:
04/11/2019
TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS and Open Redirection in the frontend login box.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024