Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-12769

Publication date:
09/05/2020
An issue was discovered in the Linux kernel before 5.4.17. drivers/spi/spi-dw.c allows attackers to cause a panic via concurrent calls to dw_spi_irq and dw_spi_transfer_one, aka CID-19b61392c5a8.
Severity CVSS v4.0: Pending analysis
Last modification:
03/05/2022

CVE-2020-12770

Publication date:
09/05/2020
An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call in a certain failure case, aka CID-83c6f2390040.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-12771

Publication date:
09/05/2020
An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadlock if a coalescing operation fails.
Severity CVSS v4.0: Pending analysis
Last modification:
26/04/2022

CVE-2019-20795

Publication date:
09/05/2020
iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option offered to end users. Even when setuid is used, other factors (such as C library configuration) may block exploitability.
Severity CVSS v4.0: Pending analysis
Last modification:
10/09/2020

CVE-2020-12765

Publication date:
09/05/2020
Solis Miolo 2.0 allows index.php?module=install&action=view&item= Directory Traversal.
Severity CVSS v4.0: Pending analysis
Last modification:
12/05/2020

CVE-2020-12764

Publication date:
09/05/2020
Gnuteca 3.8 allows file.php?folder=/&file= Directory Traversal.
Severity CVSS v4.0: Pending analysis
Last modification:
12/05/2020

CVE-2020-12766

Publication date:
09/05/2020
Gnuteca 3.8 allows action=main:search:simpleSearch SQL Injection via the exemplaryStatusId parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
12/05/2020

CVE-2020-12761

Publication date:
09/05/2020
modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow (with resultant invalid memory allocations and out-of-bounds reads) via an icon with many colors in its color map.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2019-20794

Publication date:
09/05/2020
An issue was discovered in the Linux kernel 4.18 through 5.6.11 when unprivileged user namespaces are allowed. A user can create their own PID namespace, and mount a FUSE filesystem. Upon interaction with this FUSE filesystem, if the userspace component is terminated via a kill of the PID namespace's pid 1, it will result in a hung task, and resources being permanently locked up until system reboot. This can result in resource exhaustion.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-12762

Publication date:
09/05/2020
json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2025

CVE-2020-12637

Publication date:
09/05/2020
Zulip Desktop before 5.2.0 has Missing SSL Certificate Validation because all validation was inadvertently disabled during an attempt to recognize the ignoreCerts option.
Severity CVSS v4.0: Pending analysis
Last modification:
13/05/2020

CVE-2020-12755

Publication date:
09/05/2020
fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAuthentication call even if the user had not set the keepPassword option. This may lead to unintended KWallet storage of a password.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021