Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-5350

Publication date:
15/04/2020
Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 contain a command injection vulnerability in the ACM component. A remote authenticated malicious user with root privileges could inject parameters in the ACM component APIs that could lead to manipulation of passwords and execution of malicious commands on ACM component.
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2020

CVE-2020-11791

Publication date:
15/04/2020
NETGEAR JGS516PE devices before 2.6.0.43 are affected by reflected XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2020

CVE-2020-11792

Publication date:
15/04/2020
NETGEAR R8900, R9000, RAX120, and XR700 devices before 2020-01-20 are affected by Transport Layer Security (TLS) certificate private key disclosure.
Severity CVSS v4.0: Pending analysis
Last modification:
21/04/2020

CVE-2020-3953

Publication date:
15/04/2020
Cross Site Scripting (XSS) vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-3954

Publication date:
15/04/2020
Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-5346

Publication date:
15/04/2020
RSA Authentication Manager versions prior to 8.4 P11 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the Security Console web interface. When other Security Console administrators open the affected page, the injected scripts could potentially be executed in their browser.
Severity CVSS v4.0: Pending analysis
Last modification:
30/09/2022

CVE-2020-11788

Publication date:
15/04/2020
Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.34, D7000 before 1.0.1.68, PR2000 before 1.0.0.28, R6050 before 1.0.1.18, JR6150 before 1.0.1.18, R6120 before 1.0.0.46, R6220 before 1.1.0.80, R6230 before 1.1.0.80, R6260 before 1.1.0.64, R6700v2 before 1.2.0.36, R6800 before 1.2.0.36, and R6900v2 before 1.2.0.36.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2019-20643

Publication date:
15/04/2020
NETGEAR RAX40 devices before 1.0.3.64 are affected by disclosure of sensitive information.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2019-20648

Publication date:
15/04/2020
NETGEAR RN42400 devices before 6.10.2 are affected by incorrect configuration of security settings.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2019-20649

Publication date:
15/04/2020
NETGEAR MR1100 devices before 12.06.08.00 are affected by disclosure of sensitive information.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2019-20650

Publication date:
15/04/2020
Certain NETGEAR devices are affected by denial of service. This affects R8900 before 1.0.5.2, R9000 before 1.0.5.2, XR500 before 2.3.2.56, and XR700 before 1.0.1.20.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2019-20640

Publication date:
15/04/2020
Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, D6200 before 1.1.00.32, D7000 before 1.0.1.68, JR6150 before 1.0.1.18, PR2000 before 1.0.0.28, R6020 before 1.0.0.38, R6050 before 1.0.1.18, R6080 before 1.0.0.38, R6120 before 1.0.0.46, R6220 before 1.1.0.80, R6260 before 1.1.0.40, R6700v2 before 1.2.0.36, R6800 before 1.2.0.36, R6900v2 before 1.2.0.36, WNR2020 before 1.1.0.62, and XR500 before 2.3.2.32.
Severity CVSS v4.0: Pending analysis
Last modification:
22/04/2020