Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-22783

Publication date:
28/04/2021
Etherpad
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2021

CVE-2020-22782

Publication date:
28/04/2021
Etherpad
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2021

CVE-2020-22781

Publication date:
28/04/2021
In Etherpad
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2021

CVE-2020-22784

Publication date:
28/04/2021
In Etherpad UeberDB
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2022

CVE-2020-22790

Publication date:
28/04/2021
Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby injecting arbitrary web script or HTML via modifying the name of the users. The XSS is executed when an administrator access the logs.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2021

CVE-2020-22789

Publication date:
28/04/2021
Unauthenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via the login page. The XSS is executed when an administrator accesses the logs.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2021

CVE-2021-25152

Publication date:
28/04/2021
A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
12/05/2021

CVE-2021-25165

Publication date:
28/04/2021
A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
07/05/2021

CVE-2021-25164

Publication date:
28/04/2021
A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
07/05/2021

CVE-2021-29482

Publication date:
28/04/2021
xz is a compression and decompression library focusing on the xz format completely written in Go. The function readUvarint used to read the xz container format may not terminate a loop provide malicous input. The problem has been fixed in release v0.5.8. As a workaround users can limit the size of the compressed file input to a reasonable size for their use case. The standard library had recently the same issue and got the CVE-2020-16845 allocated.
Severity CVSS v4.0: Pending analysis
Last modification:
14/05/2021

CVE-2021-25151

Publication date:
28/04/2021
A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
07/05/2021

CVE-2021-25153

Publication date:
28/04/2021
A remote SQL injection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2021