Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2017-7773

Publication date:
15/04/2019
Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2019

CVE-2017-7777

Publication date:
15/04/2019
Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2019

CVE-2017-7774

Publication date:
15/04/2019
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2019

CVE-2017-7776

Publication date:
15/04/2019
Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2019

CVE-2017-7771

Publication date:
15/04/2019
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2019

CVE-2017-18366

Publication date:
15/04/2019
Subrion CMS 4.1.5 has CSRF in blog/delete/.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2019

CVE-2017-7775

Publication date:
15/04/2019
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2018-16257

Publication date:
12/04/2019
There are multiple XSS vulnerabilities in WP All Import plugin 3.4.9 for WordPress via action=template. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2024

CVE-2018-16258

Publication date:
12/04/2019
There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-import custom_type. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2024

CVE-2018-16259

Publication date:
12/04/2019
There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-settings large_feed_limit. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2024

CVE-2019-10880

Publication date:
12/04/2019
Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2017-7772

Publication date:
12/04/2019
Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2019