Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-13595

Publication date:
31/08/2020
The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) returns the wrong number of completed BLE packets and triggers a reachable assertion on the host stack when receiving a packet with an MIC failure. An attacker within radio range can silently trigger the assertion (which disables the target's BLE stack) by sending a crafted sequence of BLE packets.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2020

CVE-2020-13655

Publication date:
31/08/2020
An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is set to movefile and the id parameter corresponds to a project the current user has access to, the file and target parameters are reflected.
Severity CVSS v4.0: Pending analysis
Last modification:
03/09/2020

CVE-2020-11618

Publication date:
31/08/2020
THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes have their TELNET service hardcoded to start on boot, which allows an attacker on the local network to achieve root access via the TELNET protocol.
Severity CVSS v4.0: Pending analysis
Last modification:
09/09/2020

CVE-2020-12646

Publication date:
31/08/2020
OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document.
Severity CVSS v4.0: Pending analysis
Last modification:
09/09/2020

CVE-2020-11617

Publication date:
31/08/2020
The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS servers, which allows a man-in-the-middle attacker to modify the data delivered to the client.
Severity CVSS v4.0: Pending analysis
Last modification:
09/09/2020

CVE-2020-24115

Publication date:
31/08/2020
In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-15020

Publication date:
31/08/2020
An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stored XSS via the Name Your Template field.
Severity CVSS v4.0: Pending analysis
Last modification:
26/05/2023

CVE-2020-4492

Publication date:
31/08/2020
IBM Spectrum Scale V5.0.0.0 through V5.0.4.3 and V4.2.0.0 through V4.2.3.21 could allow a local attacker to cause a denial of service crashing the kernel by sending a subset of ioctls on the device with invalid arguments. IBM X-Force ID: 181992.
Severity CVSS v4.0: Pending analysis
Last modification:
31/08/2020

CVE-2020-25033

Publication date:
31/08/2020
The Blubrry subscribe-sidebar (aka Subscribe Sidebar) plugin 1.3.1 for WordPress allows subscribe_sidebar.php&status= reflected XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
14/02/2024

CVE-2020-25032

Publication date:
31/08/2020
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
Severity CVSS v4.0: Pending analysis
Last modification:
28/04/2022

CVE-2020-25031

Publication date:
31/08/2020
checkinstall 1.6.2, when used to create a package that contains a symlink, may trigger the creation of a mode 0777 executable file.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2020

CVE-2020-24104

Publication date:
30/08/2020
XSS on the PIX-Link Repeater/Router LV-WR07 with firmware v28K.Router.20170904 allows attackers to steal credentials without being connected to the network. The attack vector is a crafted ESSID, as demonstrated by the wireless.htm SET2 parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
31/08/2020