Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-8226

Publication date:
17/08/2020
A vulnerability exists in phpBB
Severity CVSS v4.0: Pending analysis
Last modification:
21/08/2020

CVE-2020-13122

Publication date:
17/08/2020
The novish command-line interface, included in NoviFlow NoviWare before NW500.2.12 and deployed on NoviSwitch devices, is vulnerable to command injection in the "show status destination ipaddr" command. This could be used by a read-only user (monitoring group) or admin to execute commands on the operating system.
Severity CVSS v4.0: Pending analysis
Last modification:
21/08/2020

CVE-2020-8209

Publication date:
17/08/2020
Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.
Severity CVSS v4.0: Pending analysis
Last modification:
20/08/2020

CVE-2020-8210

Publication date:
17/08/2020
Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 discloses credentials of a service account.
Severity CVSS v4.0: Pending analysis
Last modification:
20/08/2020

CVE-2020-8211

Publication date:
17/08/2020
Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows SQL Injection.
Severity CVSS v4.0: Pending analysis
Last modification:
20/08/2020

CVE-2020-8212

Publication date:
17/08/2020
Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows access to privileged functionality.
Severity CVSS v4.0: Pending analysis
Last modification:
20/08/2020

CVE-2020-8208

Publication date:
17/08/2020
Improper input validation in Citrix XenMobile Server 10.12 before RP1, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.11 before RP6 and Citrix XenMobile Server before 10.9 RP5 allows Cross-Site Scripting (XSS).
Severity CVSS v4.0: Pending analysis
Last modification:
19/08/2020

CVE-2020-8233

Publication date:
17/08/2020
A command injection vulnerability exists in EdgeSwitch firmware
Severity CVSS v4.0: Pending analysis
Last modification:
24/05/2022

CVE-2020-8230

Publication date:
17/08/2020
A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed to corrupt memory.
Severity CVSS v4.0: Pending analysis
Last modification:
27/09/2022

CVE-2020-8232

Publication date:
17/08/2020
An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1.9.0 that allowed read only users could obtain unauthorized information through SNMP community pages.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2021

CVE-2020-9103

Publication date:
17/08/2020
HUAWEI Mate 20 smartphones with 9.0.0.205(C00E205R2P1) have a logic error vulnerability. In a special scenario, the system does not properly process. As a result, attackers can perform a series of operations to successfully establish P2P connections that are rejected by the peer end. As a result, the availability of the device is affected.
Severity CVSS v4.0: Pending analysis
Last modification:
21/08/2020

CVE-2018-7155

Publication date:
17/08/2020
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023