Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-26207

Publication date:
04/11/2020
DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening a specially crafted `.dbschema` file. The patch was released in v2.7.4.3. As a workaround, ensure `.dbschema` files from untrusted sources are not opened.
Severity CVSS v4.0: Pending analysis
Last modification:
19/11/2020

CVE-2020-27691

Publication date:
04/11/2020
The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 allows XSS via URLBlocking Settings, SNMP Settings, and System Log Settings.
Severity CVSS v4.0: Pending analysis
Last modification:
10/11/2020

CVE-2020-27690

Publication date:
04/11/2020
The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains a buffer overflow within its web management portal. When a POST request is sent to /boaform/admin/formDOMAINBLK with a large blkDomain value, the Boa server crashes.
Severity CVSS v4.0: Pending analysis
Last modification:
10/11/2020

CVE-2020-27692

Publication date:
04/11/2020
The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains multiple CSRF vulnerabilities within its web management portal. Attackers can, for example, use this to update the TR-069 configuration server settings (responsible for managing devices remotely). This makes it possible to remotely reboot the device or upload malicious firmware.
Severity CVSS v4.0: Pending analysis
Last modification:
10/11/2020

CVE-2019-7356

Publication date:
04/11/2020
Subrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
10/11/2020

CVE-2020-27689

Publication date:
04/11/2020
The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains undocumented default admin credentials for the web management interface. A remote attacker could exploit this vulnerability to login and execute commands on the device, as well as upgrade the firmware image to a malicious version.
Severity CVSS v4.0: Pending analysis
Last modification:
10/11/2020

CVE-2020-7128

Publication date:
04/11/2020
A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-7129

Publication date:
04/11/2020
A remote execution of arbitrary commands vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-28049

Publication date:
04/11/2020
An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection to the X server without providing proper authentication. A local attacker can thus access X server display contents and, for example, intercept keystrokes or access the clipboard. This is caused by a race condition during Xauthority file creation.
Severity CVSS v4.0: Pending analysis
Last modification:
15/10/2024

CVE-2020-8037

Publication date:
04/11/2020
The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-8036

Publication date:
04/11/2020
The tok2strbuf() function in tcpdump 4.10.0-PRE-GIT was used by the SOME/IP dissector in an unsafe way.
Severity CVSS v4.0: Pending analysis
Last modification:
25/11/2020

CVE-2020-22274

Publication date:
04/11/2020
JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.
Severity CVSS v4.0: Pending analysis
Last modification:
12/11/2020