Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-10742

Publication date:
07/05/2019
Axios up to and including 0.18.0 allows attackers to cause a denial of service (application crash) by continuing to accepting content after maxContentLength is exceeded.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2018-2001

Publication date:
07/05/2019
IBM Cram Social Program Management 6.1.1, 6.2.0, 7.0.4, and 7.0.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 154891.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2019-11629

Publication date:
07/05/2019
Sonatype Nexus Repository Manager 2.x before 2.14.13 allows XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
07/05/2019

CVE-2019-10869

Publication date:
07/05/2019
Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/submit page) name and tmp_name parameters.
Severity CVSS v4.0: Pending analysis
Last modification:
02/05/2022

CVE-2018-14478

Publication date:
07/05/2019
ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2018-14485

Publication date:
07/05/2019
BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.
Severity CVSS v4.0: Pending analysis
Last modification:
08/05/2019

CVE-2018-13991

Publication date:
07/05/2019
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 leaks private information in firmware images.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2018-13993

Publication date:
07/05/2019
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is prone to CSRF.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2018-13994

Publication date:
07/05/2019
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is vulnerable to a denial-of-service attack by making more than 120 connections.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2018-13992

Publication date:
07/05/2019
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by default.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-9708

Publication date:
07/05/2019
An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. A site administrator can suspend the system user (root), causing all users to be locked out from the system.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-11560

Publication date:
07/05/2019
A buffer overflow vulnerability in the streaming server provided by hisilicon in HI3516 models allows an unauthenticated attacker to remotely run arbitrary code by sending a special RTSP over HTTP packet. The vulnerability was found in many cameras using hisilicon's hardware and software, as demonstrated by TENVIS cameras 1.3.3.3, 1.2.7.2, 1.2.1.4, 7.1.20.1.2, and 13.1.1.1.7.2; FDT FD7902 11.3.14.1.3 and 10.3.14.1.3; FOSCAM cameras 3.2.1.1.1_0815 and 3.2.2.2.1_0815; and Dericam cameras V11.3.8.1.12.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021