Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-20059

Publication date:
10/02/2020
payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection. NOTE: this issue exists because of an incomplete fix for CVE-2019-19732.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-20060

Publication date:
10/02/2020
MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header. If this leaks, then third parties may discover password-reset hashes, file-delete links, or other sensitive information.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-8825

Publication date:
10/02/2020
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
30/12/2021

CVE-2020-7060

Publication date:
10/02/2020
When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause function mbfl_filt_conv_big5_wchar to read past the allocated buffer. This may lead to information disclosure or crash.
Severity CVSS v4.0: Pending analysis
Last modification:
01/07/2022

CVE-2020-7059

Publication date:
10/02/2020
When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the allocated buffer. This may lead to information disclosure or crash.
Severity CVSS v4.0: Pending analysis
Last modification:
01/07/2022

CVE-2020-8823

Publication date:
10/02/2020
htmlfile in lib/transport/htmlfile.js in SockJS before 0.3.0 is vulnerable to Reflected XSS via the /htmlfile c (aka callback) parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
12/01/2021

CVE-2020-8822

Publication date:
10/02/2020
Digi TransPort WR21 5.2.2.3, WR44 5.1.6.4, and WR44v2 5.1.6.9 devices allow stored XSS in the web application.
Severity CVSS v4.0: Pending analysis
Last modification:
11/02/2020

CVE-2017-18641

Publication date:
10/02/2020
In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.
Severity CVSS v4.0: Pending analysis
Last modification:
12/02/2020

CVE-2015-5741

Publication date:
08/02/2020
The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request that contains Content-Length and Transfer-Encoding header fields.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2021

CVE-2012-5570

Publication date:
08/02/2020
The Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allows remote authenticated users with the "access basic_webmail" permission to read arbitrary users' email addresses.
Severity CVSS v4.0: Pending analysis
Last modification:
16/03/2020

CVE-2012-4512

Publication date:
08/02/2020
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2015-3423

Publication date:
08/02/2020
Multiple SQL injection vulnerabilities in NetCracker Resource Management System before 8.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) ctrl, (2) h____%2427, (3) h____%2439, (4) param0, (5) param1, (6) param2, (7) param3, (8) param4, (9) filter_INSERT_COUNT, (10) filter_MINOR_FALLOUT, (11) filter_UPDATE_COUNT, (12) sort, or (13) sessid parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
12/02/2020