Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-10212

Publication date:
07/03/2020
upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it is possible for a DNS hostname to resolve to an internal IP address. For example, an SSRF attempt may succeed if a .ico filename is added to the PATH_INFO. Also, an attacker could create a DNS hostname that resolves to the 0.0.0.0 IP address for DNS pinning. NOTE: this issue exists because of an incomplete fix for CVE-2018-14728.
Severity CVSS v4.0: Pending analysis
Last modification:
09/03/2020

CVE-2020-8634

Publication date:
07/03/2020
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface, resulting in files being saved with world-readable and world-writable permissions. If a sensitive system file were edited this way, a low-privilege user may escalate privileges to root.
Severity CVSS v4.0: Pending analysis
Last modification:
09/03/2020

CVE-2020-10020

Publication date:
07/03/2020
Rejected reason: Number assigned to issue that does not qualify for a CVE
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-8635

Publication date:
07/03/2020
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files. This allows local users to arbitrarily create FTP users with full privileges, and escalate privileges within the operating system by modifying system files.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2017-14208

Publication date:
07/03/2020
Rejected reason: Unused CVE for 2017
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-14499

Publication date:
07/03/2020
Rejected reason: Unused CVE for 2019
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-14500

Publication date:
07/03/2020
Rejected reason: Unused CVE for 2019
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-14501

Publication date:
07/03/2020
Rejected reason: Unused CVE for 2019
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-14502

Publication date:
07/03/2020
Rejected reason: Unused CVE for 2019
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-14503

Publication date:
07/03/2020
Rejected reason: Unused CVE for 2019
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-14504

Publication date:
07/03/2020
Rejected reason: Unused CVE for 2019
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-14505

Publication date:
07/03/2020
Rejected reason: Unused CVE for 2019
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023