Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-12704

Publication date:
07/05/2020
UliCMS before 2020.2 has PageController stored XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
08/05/2020

CVE-2020-12703

Publication date:
07/05/2020
UliCMS before 2020.2 has XSS during PackageController uninstall.
Severity CVSS v4.0: Pending analysis
Last modification:
08/05/2020

CVE-2020-11047

Publication date:
07/05/2020
In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_measure_results. A malicious server can extract up to 8 bytes of client memory with a manipulated message by providing a short input and reading the measurement result data. This has been patched in 2.0.0.
Severity CVSS v4.0: Pending analysis
Last modification:
24/10/2023

CVE-2020-4429

Publication date:
07/05/2020
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account. A remote attacker could exploit this vulnerability to login and execute arbitrary code on the system with root privileges. IBM X-Force ID: 180534.
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2025

CVE-2020-4427

Publication date:
07/05/2020
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532.
Severity CVSS v4.0: Pending analysis
Last modification:
04/11/2025

CVE-2020-4428

Publication date:
07/05/2020
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533.
Severity CVSS v4.0: Pending analysis
Last modification:
04/11/2025

CVE-2020-4430

Publication date:
07/05/2020
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to download arbitrary files from the system. IBM X-Force ID: 180535.
Severity CVSS v4.0: Pending analysis
Last modification:
04/11/2025

CVE-2020-11042

Publication date:
07/05/2020
In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_info. It allows reading a attacker-defined amount of client memory (32bit unsigned -> 4GB) to an intermediate buffer. This can be used to crash the client or store information for later retrieval. This has been patched in 2.0.0.
Severity CVSS v4.0: Pending analysis
Last modification:
24/10/2023

CVE-2020-11044

Publication date:
07/05/2020
In FreeRDP greater than 1.2 and before 2.0.0, a double free in update_read_cache_bitmap_v3_order crashes the client application if corrupted data from a manipulated server is parsed. This has been patched in 2.0.0.
Severity CVSS v4.0: Pending analysis
Last modification:
24/10/2023

CVE-2020-11045

Publication date:
07/05/2020
In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bound read in in update_read_bitmap_data that allows client memory to be read to an image buffer. The result displayed on screen as colour.
Severity CVSS v4.0: Pending analysis
Last modification:
24/10/2023

CVE-2020-11046

Publication date:
07/05/2020
In FreeRDP after 1.0 and before 2.0.0, there is a stream out-of-bounds seek in update_read_synchronize that could lead to a later out-of-bounds read.
Severity CVSS v4.0: Pending analysis
Last modification:
24/10/2023

CVE-2020-10972

Publication date:
07/05/2020
An issue was discovered where a page is exposed that has the current administrator password in cleartext in the source code of the page. No authentication is required in order to reach the page (a certain live_?.shtml page with the variable syspasswd). Affected Devices: Wavlink WN530HG4, Wavlink WN531G3, and Wavlink WN572HG3
Severity CVSS v4.0: Pending analysis
Last modification:
29/04/2022