Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-27988

Publication date:
16/11/2020
Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).
Severity CVSS v4.0: Pending analysis
Last modification:
17/11/2020

CVE-2020-27623

Publication date:
16/11/2020
JetBrains IdeaVim before version 0.58 might have caused an information leak in limited circumstances.
Severity CVSS v4.0: Pending analysis
Last modification:
30/11/2020

CVE-2020-27627

Publication date:
16/11/2020
JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.
Severity CVSS v4.0: Pending analysis
Last modification:
01/12/2020

CVE-2020-27622

Publication date:
16/11/2020
In JetBrains IntelliJ IDEA before 2020.2, the built-in web server could expose information about the IDE version.
Severity CVSS v4.0: Pending analysis
Last modification:
23/11/2020

CVE-2020-27423

Publication date:
16/11/2020
Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox
Severity CVSS v4.0: Pending analysis
Last modification:
01/12/2020

CVE-2020-25952

Publication date:
16/11/2020
SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
Severity CVSS v4.0: Pending analysis
Last modification:
27/12/2024

CVE-2020-27191

Publication date:
16/11/2020
LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted string in the index.php f1 variable, aka Local File Inclusion. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Severity CVSS v4.0: Pending analysis
Last modification:
30/11/2020

CVE-2020-27422

Publication date:
16/11/2020
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.
Severity CVSS v4.0: Pending analysis
Last modification:
30/11/2020

CVE-2020-26129

Publication date:
16/11/2020
In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible.
Severity CVSS v4.0: Pending analysis
Last modification:
01/12/2020

CVE-2020-13772

Publication date:
16/11/2020
In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about the server operating system, local pathnames, and environment variables with no authentication required.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2020

CVE-2020-13769

Publication date:
16/11/2020
LDMS/alert_log.aspx in Ivanti Endpoint Manager through 2020.1 allows SQL Injection via a /remotecontrolauth/api/device request.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2020

CVE-2020-13773

Publication date:
16/11/2020
Ivanti Endpoint Manager through 2020.1.1 allows XSS via /LDMS/frm_splitfrm.aspx, /LDMS/licensecheck.aspx, /LDMS/frm_splitcollapse.aspx, /LDMS/alert_log.aspx, /LDMS/ServerList.aspx, /LDMS/frm_coremainfrm.aspx, /LDMS/frm_findfrm.aspx, /LDMS/frm_taskfrm.aspx, and /LDMS/query_browsecomp.aspx.
Severity CVSS v4.0: Pending analysis
Last modification:
27/11/2020