Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-26649

Publication date:
22/10/2020
AtomXCMS 2.0 is affected by Incorrect Access Control via admin/dump.php
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-26650

Publication date:
22/10/2020
AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-24033

Publication date:
22/10/2020
An issue was discovered in fs.com S3900 24T4S 1.7.0 and earlier. The form does not have an authentication or token authentication mechanism that allows remote attackers to forge requests on behalf of a site administrator to change all settings including deleting users, creating new users with escalated privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
02/11/2020

CVE-2020-27646

Publication date:
22/10/2020
Biscom Secure File Transfer (SFT) before 5.1.1082 and 6.x before 6.0.1011 allows user credential theft.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-27560

Publication date:
22/10/2020
ImageMagick 7.0.10-34 allows Division by Zero in OptimizeLayerFrames in MagickCore/layer.c, which may cause a denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
11/03/2023

CVE-2020-27642

Publication date:
22/10/2020
A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.
Severity CVSS v4.0: Pending analysis
Last modification:
27/10/2020

CVE-2020-27638

Publication date:
22/10/2020
receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-27621

Publication date:
22/10/2020
The FileImporter extension in MediaWiki through 1.35.0 was not properly attributing various user actions to a specific user's IP address. Instead, for various actions, it would report the IP address of an internal Wikimedia Foundation server by omitting X-Forwarded-For data. This resulted in an inability to properly audit and attribute various user actions performed via the FileImporter extension.
Severity CVSS v4.0: Pending analysis
Last modification:
02/11/2020

CVE-2020-27620

Publication date:
22/10/2020
The Cosmos Skin for MediaWiki through 1.35.0 has stored XSS because MediaWiki messages were not being properly escaped. This is related to wfMessage and Html::rawElement, as demonstrated by CosmosSocialProfile::getUserGroups.
Severity CVSS v4.0: Pending analysis
Last modification:
26/10/2020

CVE-2020-27619

Publication date:
22/10/2020
In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.
Severity CVSS v4.0: Pending analysis
Last modification:
03/02/2024

CVE-2020-17454

Publication date:
21/10/2020
WSO2 API Manager 3.1.0 and earlier has reflected XSS on the "publisher" component's admin interface. More precisely, it is possible to inject an XSS payload into the owner POST parameter, which does not filter user inputs. By putting an XSS payload in place of a valid Owner Name, a modal box appears that writes an error message concatenated to the injected payload (without any form of data encoding). This can also be exploited via CSRF.
Severity CVSS v4.0: Pending analysis
Last modification:
26/10/2020

CVE-2020-24421

Publication date:
21/10/2020
Adobe InDesign version 15.1.2 (and earlier) is affected by a NULL pointer dereference bug that occurs when handling a malformed .indd file. The impact is limited to causing a denial-of-service of the client application. User interaction is required to exploit this issue.
Severity CVSS v4.0: Pending analysis
Last modification:
10/12/2021