Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-20653

Publication date:
15/04/2020
Certain NETGEAR devices are affected by denial of service. This affects WAC505 before 8.0.6.4 and WAC510 before 8.0.6.4.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2019-20654

Publication date:
15/04/2020
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects WAC505 before 8.0.6.4 and WAC510 before 8.0.6.4.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2019-12524

Publication date:
15/04/2020
An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid by default comes with rules to block access to the Cache Manager, which serves detailed server information meant for the maintainer. This rule is implemented via url_regex. The handler for url_regex rules URL decodes an incoming request. This allows an attacker to encode their URL to bypass the url_regex check, and gain access to the blocked resource.
Severity CVSS v4.0: Pending analysis
Last modification:
09/02/2021

CVE-2019-20651

Publication date:
15/04/2020
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WAC505 before 8.2.1.16 and WAC510 before 8.2.1.16.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2020-11789

Publication date:
15/04/2020
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R7900 before 1.0.3.10.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-11790

Publication date:
15/04/2020
NETGEAR R7800 devices before 1.0.2.68 are affected by remote code execution by unauthenticated attackers.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-5350

Publication date:
15/04/2020
Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 contain a command injection vulnerability in the ACM component. A remote authenticated malicious user with root privileges could inject parameters in the ACM component APIs that could lead to manipulation of passwords and execution of malicious commands on ACM component.
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2020

CVE-2020-11791

Publication date:
15/04/2020
NETGEAR JGS516PE devices before 2.6.0.43 are affected by reflected XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2020

CVE-2020-11792

Publication date:
15/04/2020
NETGEAR R8900, R9000, RAX120, and XR700 devices before 2020-01-20 are affected by Transport Layer Security (TLS) certificate private key disclosure.
Severity CVSS v4.0: Pending analysis
Last modification:
21/04/2020

CVE-2020-3953

Publication date:
15/04/2020
Cross Site Scripting (XSS) vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-3954

Publication date:
15/04/2020
Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-5346

Publication date:
15/04/2020
RSA Authentication Manager versions prior to 8.4 P11 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the Security Console web interface. When other Security Console administrators open the affected page, the injected scripts could potentially be executed in their browser.
Severity CVSS v4.0: Pending analysis
Last modification:
30/09/2022