Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-20046

Publication date:
14/02/2020
The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and prior. The affected product does not require adequate authentication, which may allow an attacker to read sensitive information or execute arbitrary code. This is a different issue than CVE-2019-16879 and CVE-2019-20045.
Severity CVSS v4.0: Pending analysis
Last modification:
25/02/2020

CVE-2019-19879

Publication date:
14/02/2020
HashiCorp Sentinel up to 0.10.1 incorrectly parsed negation in certain policy expressions. Fixed in 0.10.2.
Severity CVSS v4.0: Pending analysis
Last modification:
25/02/2020

CVE-2019-19762

Publication date:
14/02/2020
Rejected reason: Unused CVE for 2019
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-19763

Publication date:
14/02/2020
Rejected reason: Unused CVE for 2019
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-19764

Publication date:
14/02/2020
Rejected reason: Unused CVE for 2019
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-19765

Publication date:
14/02/2020
Rejected reason: Unused CVE for 2019
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-6190

Publication date:
14/02/2020
Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep (S3) on systems with Intel TXT enabled.
Severity CVSS v4.0: Pending analysis
Last modification:
16/03/2020

CVE-2019-19757

Publication date:
14/02/2020
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulnerability in versions prior to 2.6.6 that could allow JavaScript code to be executed in the user's web browser if a specially crafted link is visited. The JavaScript code is executed on the user's system, not executed on LXCA itself.
Severity CVSS v4.0: Pending analysis
Last modification:
24/02/2020

CVE-2019-19758

Publication date:
14/02/2020
A vulnerability in the web interface of Lenovo EZ Media & Backup Center, ix2 & ix2-dl version 4.1.406.34763 and prior could allow an unauthenticated, remote attacker to redirect a user to an untrusted web page.
Severity CVSS v4.0: Pending analysis
Last modification:
27/02/2020

CVE-2019-20455

Publication date:
14/02/2020
Gateways/Gateway.php in Heartland & Global Payments PHP SDK before 2.0.0 does not enforce SSL certificate validations.
Severity CVSS v4.0: Pending analysis
Last modification:
14/02/2024

CVE-2018-21033

Publication date:
14/02/2020
A vulnerability in Hitachi Command Suite prior to 8.6.2-00, Hitachi Automation Director prior to 8.6.2-00 and Hitachi Infrastructure Analytics Advisor prior to 4.2.0-00 allow authenticated remote users to load an arbitrary Cascading Style Sheets (CSS) token sequence. Hitachi Command Suite includes Hitachi Device Manager, Hitachi Tiered Storage Manager, Hitachi Replication Manager, Hitachi Tuning Manager, Hitachi Global Link Manager and Hitachi Compute Systems Manager.
Severity CVSS v4.0: Pending analysis
Last modification:
27/02/2020

CVE-2018-21032

Publication date:
14/02/2020
A vulnerability in Hitachi Command Suite prior to 8.7.1-00 and Hitachi Automation Director prior to 8.5.0-00 allow authenticated remote users to expose technical information through error messages. Hitachi Command Suite includes Hitachi Device Manager and Hitachi Compute Systems Manager.
Severity CVSS v4.0: Pending analysis
Last modification:
27/02/2020