Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-14524

Publication date:
02/08/2019
An issue was discovered in Schism Tracker through 20190722. There is a heap-based buffer overflow via a large number of song patterns in fmt_mtm_load_song in fmt/mtm.c, a different vulnerability than CVE-2019-14465.
Severity CVSS v4.0: Pending analysis
Last modification:
03/03/2023

CVE-2019-14517

Publication date:
01/08/2019
pandao Editor.md 1.5.0 allows XSS via the Javascript: string.
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2019

CVE-2019-5401

Publication date:
01/08/2019
A potential security vulnerability has been identified in HP2910al-48G version W.15.14.0016. The attack exploits an xss injection by setting the attack vector in one of the switch persistent configuration fields (management URL, location, contact). But admin privileges are required to configure these fields thereby reducing the likelihood of exploit. HPE Aruba has provided firmware updates to resolve the vulnerability in HP 2910-48G al Switch. Please update to W.15.14.0017.
Severity CVSS v4.0: Pending analysis
Last modification:
08/08/2019

CVE-2019-14513

Publication date:
01/08/2019
Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that result in a read operation beyond the buffer allocated for the packet, a different vulnerability than CVE-2017-14491.
Severity CVSS v4.0: Pending analysis
Last modification:
03/03/2023

CVE-2019-14260

Publication date:
01/08/2019
On the Alcatel-Lucent Enterprise (ALE) 8008 Cloud Edition Deskphone VoIP phone with firmware 1.50.13, a command injection (missing input validation) issue in the password change field for the Change Password interface allows an authenticated remote attacker in the same network to trigger OS commands via shell commands in a POST request.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2016-10826

Publication date:
01/08/2019
cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93).
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2019

CVE-2016-10821

Publication date:
01/08/2019
In cPanel before 55.9999.141, Scripts/addpop reveals a command-line password in a process list (SEC-75).
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2019

CVE-2016-10820

Publication date:
01/08/2019
cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31).
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2019

CVE-2016-10819

Publication date:
01/08/2019
In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125).
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2019

CVE-2016-10818

Publication date:
01/08/2019
cPanel before 57.9999.54 incorrectly sets log-file permissions in dnsadmin-startup and spamd-startup (SEC-124).
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2019

CVE-2016-10817

Publication date:
01/08/2019
cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123).
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2019

CVE-2016-10816

Publication date:
01/08/2019
cPanel before 57.9999.54 allows Webmail accounts to execute arbitrary code through forwarders (SEC-121).
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2019