Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-41826

Publication date:
30/09/2021
PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect.
Severity CVSS v4.0: Pending analysis
Last modification:
07/10/2021

CVE-2021-41824

Publication date:
30/09/2021
Craft CMS before 3.7.14 allows CSV injection.
Severity CVSS v4.0: Pending analysis
Last modification:
30/11/2021

CVE-2020-20781

Publication date:
29/09/2021
A stored cross-site scripting (XSS) vulnerability in /ucms/index.php?do=list_edit of UCMS 1.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title, key words, description or content text fields.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2021

CVE-2021-41821

Publication date:
29/09/2021
Wazuh Manager in Wazuh through 4.1.5 is affected by a remote Integer Underflow vulnerability that might lead to denial of service. A crafted message must be sent from an authenticated agent to the manager.
Severity CVSS v4.0: Pending analysis
Last modification:
12/10/2021

CVE-2020-20128

Publication date:
29/09/2021
LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2021

CVE-2020-20129

Publication date:
29/09/2021
LaraCMS v1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the content editor.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2021

CVE-2020-20131

Publication date:
29/09/2021
LaraCMS v1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows atackers to execute arbitrary web scripts or HTML via a crafted payload in the page management module.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2021

CVE-2021-41034

Publication date:
29/09/2021
The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint. As a consequence the builds of such stacks are vulnerable to MITM attacks that allow the replacement of the original binaries with arbitrary ones. The stacks involved are Java 8 (alpine and centos), Android and PHP. The vulnerability is not exploitable at runtime but only when building Che.
Severity CVSS v4.0: Pending analysis
Last modification:
07/10/2021

CVE-2021-41795

Publication date:
29/09/2021
The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to authorization bypass. By targeting a vulnerable component of this extension, a malicious web page could read a subset of 1Password vault items that would normally be fillable by the user on that web page. These items are usernames and passwords for vault items associated with its domain, usernames and passwords without a domain association, credit cards, and contact items. (1Password must be unlocked for these items to be accessible, but no further user interaction is required.)
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2022

CVE-2021-41764

Publication date:
29/09/2021
A cross-site request forgery (CSRF) vulnerability exists in Streama up to and including v1.10.3. The application does not have CSRF checks in place when performing actions such as uploading local files. As a result, attackers could make a logged-in administrator upload arbitrary local files via a CSRF attack and send them to the attacker.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2021

CVE-2021-35945

Publication date:
29/09/2021
Couchbase Server 6.5.x, 6.6.0 through 6.6.2, and 7.0.0, has a Buffer Overflow. A specially crafted network packet sent from an attacker can crash memcached.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2021

CVE-2021-35944

Publication date:
29/09/2021
Couchbase Server 6.5.x, 6.6.x through 6.6.2, and 7.0.0 has a Buffer Overflow. A specially crafted network packet sent from an attacker can crash memcached.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2021