Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-13128

Publication date:
18/05/2020
An issue was discovered in Manolo GWTUpload 1.0.3. server/UploadServlet.java (the servlet for handling file upload) accepts a delay parameter that causes a thread to sleep. It can be abused to cause all of a server's threads to sleep, leading to denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
19/05/2020

CVE-2019-20802

Publication date:
18/05/2020
An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server improperly displays directory names, leading to Stored XSS, which may be used to steal a user's data. This requires user interaction because there is no known direct way for an attacker to create a crafted directory name on a victim's device. However, a crafted directory name can occur if a victim extracts a ZIP archive that was provided by an attacker.
Severity CVSS v4.0: Pending analysis
Last modification:
19/05/2020

CVE-2019-20797

Publication date:
18/05/2020
An issue was discovered in e6y prboom-plus 2.5.1.5. There is a buffer overflow in client and server code responsible for handling received UDP packets, as demonstrated by I_SendPacket or I_SendPacketTo in i_network.c.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-4345

Publication date:
17/05/2020
IBM i 7.2, 7.3, and 7.4 users running complex SQL statements under a specific set of circumstances may allow a local user to obtain sensitive information that they should not have access to. IBM X-Force ID: 178318.
Severity CVSS v4.0: Pending analysis
Last modification:
18/05/2020

CVE-2020-13125

Publication date:
17/05/2020
An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-13126

Publication date:
17/05/2020
An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary executable files to achieve remote code execution. NOTE: the free Elementor plugin is unaffected.
Severity CVSS v4.0: Pending analysis
Last modification:
25/08/2020

CVE-2020-13121

Publication date:
16/05/2020
Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.
Severity CVSS v4.0: Pending analysis
Last modification:
18/05/2020

CVE-2020-13118

Publication date:
16/05/2020
An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the parameter community.
Severity CVSS v4.0: Pending analysis
Last modification:
19/05/2020

CVE-2020-13111

Publication date:
16/05/2020
NaviServer 4.99.4 to 4.99.19 allows denial of service due to the nsd/driver.c ChunkedDecode function not properly validating the length of a chunk. A remote attacker can craft a chunked-transfer request that will result in a negative value being passed to memmove via the size parameter, causing the process to crash.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-13110

Publication date:
16/05/2020
The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of malicious DLLs through use of the kerberos_sspi LoadLibrary() method, because of a DLL path search.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-13109

Publication date:
16/05/2020
Morita Shogi 64 through 2020-05-02 for Nintendo 64 devices allows remote attackers to execute arbitrary code via crafted packet data to the built-in modem because 0x800b3e94 (aka the IF subcommand to top-level command 7) has a stack-based buffer overflow.
Severity CVSS v4.0: Pending analysis
Last modification:
20/05/2020

CVE-2020-12872

Publication date:
15/05/2020
yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if running on an Erlang/OTP virtual machine with a version less than 21.0.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023