Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-7494

Publication date:
16/06/2020
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the project file.
Severity CVSS v4.0: Pending analysis
Last modification:
19/06/2020

CVE-2020-7495

Publication date:
16/06/2020
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability during zip file extraction exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause unauthorized write access outside of expected path folder when opening the project file.
Severity CVSS v4.0: Pending analysis
Last modification:
19/06/2020

CVE-2020-7497

Publication date:
16/06/2020
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause arbitrary application execution when the computer starts.
Severity CVSS v4.0: Pending analysis
Last modification:
19/06/2020

CVE-2020-13162

Publication date:
16/06/2020
A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down to 5.3 R70 for Windows (which runs as NT AUTHORITY/SYSTEM) allows unprivileged users to run a Microsoft Installer executable with elevated privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2025

CVE-2020-14199

Publication date:
16/06/2020
BIP-143 in the Bitcoin protocol specification mishandles the signing of a Segwit transaction, which allows attackers to trick a user into making two signatures in certain cases, potentially leading to a huge transaction fee. NOTE: this affects all hardware wallets. It was fixed in 1.9.1 for the Trezor One and 2.3.1 for the Trezor Model T.
Severity CVSS v4.0: Pending analysis
Last modification:
23/06/2020

CVE-2020-10268

Publication date:
16/06/2020
Critical services for operation can be terminated from windows task manager, bringing the manipulator to a halt. After this a Re-Calibration of the brakes needs to be performed. Be noted that this only can be accomplished either by a Kuka technician or by Kuka issued calibration hardware that interfaces with the manipulator furthering the delay and increasing operational costs.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-14195

Publication date:
16/06/2020
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).
Severity CVSS v4.0: Pending analysis
Last modification:
17/11/2021

CVE-2020-8542

Publication date:
16/06/2020
OX App Suite through 7.10.3 allows XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
08/04/2022

CVE-2020-4320

Publication date:
16/06/2020
IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD do not correctly block or allow clients based on the certificate distinguished name SSLPEER setting. IBM X-Force ID: 177403.
Severity CVSS v4.0: Pending analysis
Last modification:
23/06/2020

CVE-2020-8541

Publication date:
16/06/2020
OX App Suite through 7.10.3 allows XXE attacks.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2020

CVE-2020-8544

Publication date:
16/06/2020
OX App Suite through 7.10.3 allows SSRF.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2020

CVE-2020-9522

Publication date:
16/06/2020
Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, Affecting versions 7.0.x, 7.2 and 7.2.1 . The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023