Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2016-11020

Publication date:
25/02/2020
Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
03/03/2020

CVE-2020-9018

Publication date:
25/02/2020
LiteCart through 2.2.1 allows admin/?app=users&doc=edit_user CSRF to add a user.
Severity CVSS v4.0: Pending analysis
Last modification:
26/02/2020

CVE-2020-9019

Publication date:
25/02/2020
The WPJobBoard plugin 5.5.3 for WordPress allows Persistent XSS via the Add Job form, as demonstrated by title and Description.
Severity CVSS v4.0: Pending analysis
Last modification:
01/01/2022

CVE-2020-9008

Publication date:
25/02/2020
Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web script via the Tile widget in the People Tool profile editor.
Severity CVSS v4.0: Pending analysis
Last modification:
09/03/2020

CVE-2020-9391

Publication date:
25/02/2020
An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to move upwards, aka CID-dcde237319e6. This has been observed to cause heap corruption with the GNU C Library malloc implementation.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-9335

Publication date:
25/02/2020
Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploitation of this vulnerability would allow a authenticated admin user to inject arbitrary JavaScript code that is viewed by other users.
Severity CVSS v4.0: Pending analysis
Last modification:
25/02/2020

CVE-2020-8793

Publication date:
25/02/2020
OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in smtpd.c.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-8794

Publication date:
25/02/2020
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the server code launches the client code during bounce handling.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-9017

Publication date:
25/02/2020
LiteCart through 2.2.1 allows CSV injection via a customer's profile.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-9334

Publication date:
25/02/2020
A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitation of this vulnerability would allow a authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users.
Severity CVSS v4.0: Pending analysis
Last modification:
23/05/2023

CVE-2019-12863

Publication date:
25/02/2020
SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) allows Stored HTML Injection by administrators via the Web Console Settings screen.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-5162

Publication date:
25/02/2020
An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
13/06/2022