Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-16317

Publication date:
14/09/2019
In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in a filename parameter, because PHAR uploads are not blocked and are reachable within the phar://../../../../../../../../var/www/html/web/var/assets/ directory, a different vulnerability than CVE-2019-10867 and CVE-2019-16318.
Severity CVSS v4.0: Pending analysis
Last modification:
17/09/2019

CVE-2019-16318

Publication date:
14/09/2019
In Pimcore before 5.7.1, an attacker with limited privileges can bypass file-extension restrictions via a 256-character filename, as demonstrated by the failure of automatic renaming of .php to .php.txt for long filenames, a different vulnerability than CVE-2019-10867 and CVE-2019-16317.
Severity CVSS v4.0: Pending analysis
Last modification:
17/09/2019

CVE-2019-16307

Publication date:
14/09/2019
A Reflected Cross-Site Scripting (XSS) vulnerability in the webEx module in webExMeetingLogin.jsp and deleteWebExMeetingCheck.jsp in Fuji Xerox DocuShare through 7.0.0.C1.609 allows remote attackers to inject arbitrary web script or HTML via the handle parameter (webExMeetingLogin.jsp) and meetingKey parameter (deleteWebExMeetingCheck.jsp).
Severity CVSS v4.0: Pending analysis
Last modification:
09/02/2022

CVE-2019-16309

Publication date:
14/09/2019
FlameCMS 3.3.5 has SQL injection in account/login.php via accountName.
Severity CVSS v4.0: Pending analysis
Last modification:
16/09/2019

CVE-2019-16310

Publication date:
14/09/2019
NIUSHOP V1.11 has XSS via the index.php?s=/admin URI.
Severity CVSS v4.0: Pending analysis
Last modification:
16/09/2019

CVE-2019-16311

Publication date:
14/09/2019
NIUSHOP V1.11 has CSRF via search_info to index.php.
Severity CVSS v4.0: Pending analysis
Last modification:
16/09/2019

CVE-2019-16312

Publication date:
14/09/2019
s-cms V3.0 has XSS in index.php?type=text via the S_id parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
16/09/2019

CVE-2019-16313

Publication date:
14/09/2019
ifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-16294

Publication date:
14/09/2019
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.
Severity CVSS v4.0: Pending analysis
Last modification:
28/02/2023

CVE-2019-16314

Publication date:
14/09/2019
Indexhibit 2.1.5 allows a product reinstallation, with resultant remote code execution, via /ndxzstudio/install.php?p=2.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2019-16305

Publication date:
14/09/2019
In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup asking whether the user wants to run MobaXterm to handle the link. If accepted, another popup appears asking for further confirmation. If this is also accepted, command execution is achieved, as demonstrated by the MobaXterm://`calc` URI.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-16303

Publication date:
14/09/2019
A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an insecure source of randomness (apache.commons.lang3 RandomStringUtils). This allows an attacker (if able to obtain their own password reset URL) to compute the value for all other password resets for other accounts, thus allowing privilege escalation or account takeover.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023