Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-20835

Publication date:
30/04/2019
A vulnerability was found in tar-fs before 1.16.2. An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content.
Severity CVSS v4.0: Pending analysis
Last modification:
03/05/2019

CVE-2018-20834

Publication date:
30/04/2019
A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2).
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2019

CVE-2019-10131

Publication date:
30/04/2019
An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the formatIPTCfromBuffer function in coders/meta.c. A local attacker may use this flaw to read beyond the end of the buffer or to crash the program.
Severity CVSS v4.0: Pending analysis
Last modification:
28/10/2021

CVE-2019-11193

Publication date:
30/04/2019
The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass the CSRF protection with this, and take over the administration panel.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2018-15208

Publication date:
30/04/2019
BPC SmartVista 2 has Session Fixation via the JSESSIONID parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
01/05/2019

CVE-2018-15206

Publication date:
30/04/2019
BPC SmartVista 2 has CSRF via SVFE2/pages/admpages/roles/createrole.jsf.
Severity CVSS v4.0: Pending analysis
Last modification:
01/05/2019

CVE-2018-14874

Publication date:
30/04/2019
An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. Input passed through the code parameter in three pages as collaterals/colexe3t.jsp and /references/refsuppu.jsp and /references/refbranu.jsp is mishandled before being used in SQL queries, allowing SQL injection with an authenticated session.
Severity CVSS v4.0: Pending analysis
Last modification:
03/05/2019

CVE-2018-14931

Publication date:
30/04/2019
An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. An open redirect exists via a /IntellectMain.jsp?IntellectSystem= URI.
Severity CVSS v4.0: Pending analysis
Last modification:
03/05/2019

CVE-2018-14875

Publication date:
30/04/2019
An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. Reflected XSS exists with an authenticated session via the Customerid, formName, FrameId, or MODE parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
03/05/2019

CVE-2018-14930

Publication date:
30/04/2019
An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. CSRF can occur via a /CollatWebApp/gcmsRefInsert?name=SUPP URI.
Severity CVSS v4.0: Pending analysis
Last modification:
03/05/2019

CVE-2018-15207

Publication date:
30/04/2019
BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a normal user is able to access the SVFE2/pages/finadmin/currconvrate/currconvrate.jsf functionality that should be only accessible to an admin.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2019-9621

Publication date:
30/04/2019
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2025