Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2016-4572

Publication date:
26/11/2019
In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
10/12/2019

CVE-2016-3131

Publication date:
26/11/2019
Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.
Severity CVSS v4.0: Pending analysis
Last modification:
10/12/2019

CVE-2016-3192

Publication date:
26/11/2019
Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files.
Severity CVSS v4.0: Pending analysis
Last modification:
04/12/2019

CVE-2015-6495

Publication date:
26/11/2019
There is Sensitive Information in Cloudera Manager before 5.4.6 Diagnostic Support Bundles.
Severity CVSS v4.0: Pending analysis
Last modification:
03/12/2019

CVE-2019-14853

Publication date:
26/11/2019
An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
17/12/2019

CVE-2019-14857

Publication date:
26/11/2019
A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect issue exists in URLs with trailing slashes similar to CVE-2019-3877 in mod_auth_mellon.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-14890

Publication date:
26/11/2019
A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the Ansible Tower license.
Severity CVSS v4.0: Pending analysis
Last modification:
17/12/2019

CVE-2011-4350

Publication date:
26/11/2019
Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain content of arbitrary local files via specially-crafted URL request.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2011-4121

Publication date:
26/11/2019
The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation. A remote attacker could use this flaw to bypass or corrupt integrity of services, depending on strong private RSA keys generation mechanism.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2011-4120

Publication date:
26/11/2019
Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common authentication process and obtain access to the account in question by providing a NULL value (pressing Ctrl-D keyboard sequence) as the password string.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2011-4090

Publication date:
26/11/2019
Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2011-4082

Publication date:
26/11/2019
A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP header. A remote attacker could use this flaw to cause a denial of service via specially-crafted request.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024