Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-35338

Publication date:
14/12/2020
The Web Administrative Interface in Mobile Viewpoint Wireless Multiplex Terminal (WMT) Playout Server 20.2.8 and earlier has a default account with a password of "pokon."
Severity CVSS v4.0: Pending analysis
Last modification:
15/12/2020

CVE-2020-28856

Publication date:
14/12/2020
OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP address, allowing attackers to spoof it using X-Forwarded-For in the header, by supplying localhost address such as 127.0.0.1, effectively bypassing all IP address based access controls.
Severity CVSS v4.0: Pending analysis
Last modification:
15/12/2020

CVE-2020-25175

Publication date:
14/12/2020
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
Severity CVSS v4.0: Pending analysis
Last modification:
30/04/2021

CVE-2020-25179

Publication date:
14/12/2020
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2021

CVE-2020-15733

Publication date:
14/12/2020
An Origin Validation Error vulnerability in the SafePay component of Bitdefender Antivirus Plus allows a web resource to misrepresent itself in the URL bar. This issue affects: Bitdefender Antivirus Plus versions prior to 25.0.7.29.
Severity CVSS v4.0: Pending analysis
Last modification:
16/12/2020

CVE-2020-35382

Publication date:
14/12/2020
SQL Injection in Classbooking before 2.4.1 via the username field of a CSV file when adding a new user.
Severity CVSS v4.0: Pending analysis
Last modification:
14/12/2020

CVE-2020-14268

Publication date:
14/12/2020
A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the client or inject code into the system which would execute with the privileges of the client.
Severity CVSS v4.0: Pending analysis
Last modification:
15/12/2020

CVE-2020-35378

Publication date:
14/12/2020
SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands and bypass authentication via the username and password fields.
Severity CVSS v4.0: Pending analysis
Last modification:
14/12/2020

CVE-2020-14244

Publication date:
14/12/2020
A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the server or inject code into the system which would execute with the privileges of the server.
Severity CVSS v4.0: Pending analysis
Last modification:
16/12/2020

CVE-2020-29227

Publication date:
14/12/2020
An issue was discovered in Car Rental Management System 1.0. An unauthenticated user can perform a file inclusion attack against the /index.php file with a partial filename in the "page" parameter, to cause local file inclusion resulting in code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
15/12/2020

CVE-2020-17513

Publication date:
14/12/2020
In Apache Airflow versions prior to 1.10.13, the Charts and Query View of the old (Flask-admin based) UI were vulnerable for SSRF attack.
Severity CVSS v4.0: Pending analysis
Last modification:
15/12/2020

CVE-2020-17511

Publication date:
14/12/2020
In Airflow versions prior to 1.10.13, when creating a user using airflow CLI, the password gets logged in plain text in the Log table in Airflow Metadatase. Same happened when creating a Connection with a password field.
Severity CVSS v4.0: Pending analysis
Last modification:
15/12/2020