Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-4444

Publication date:
16/12/2019
IBM API Connect 2018.1 through 2018.4.1.7 Developer Portal's user registration page does not disable password autocomplete. An attacker with access to the browser instance and local system credentials can steal the credentials used for registration. IBM X-Force ID: 163453.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-19368

Publication date:
16/12/2019
A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1. An attacker can exploit it by sending a crafted link to end users and can execute arbitrary Javascripts
Severity CVSS v4.0: Pending analysis
Last modification:
23/12/2019

CVE-2019-19783

Publication date:
16/12/2019
An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges, because of folder mishandling in autosieve_createfolder() in imap/lmtp_sieve.c.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-19807

Publication date:
15/12/2019
In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is related to snd_timer_open and snd_timer_close_locked. The timeri variable was originally intended to be for a newly created timer instance, but was used for a different purpose after refactoring.
Severity CVSS v4.0: Pending analysis
Last modification:
17/01/2023

CVE-2014-8650

Publication date:
15/12/2019
python-requests-Kerberos through 0.5 does not handle mutual authentication
Severity CVSS v4.0: Pending analysis
Last modification:
19/12/2019

CVE-2014-3643

Publication date:
15/12/2019
jersey: XXE via parameter entities not disabled by the jersey SAX parser
Severity CVSS v4.0: Pending analysis
Last modification:
25/07/2022

CVE-2014-8561

Publication date:
15/12/2019
imagemagick 6.8.9.6 has remote DOS via infinite loop
Severity CVSS v4.0: Pending analysis
Last modification:
19/12/2019

CVE-2014-3652

Publication date:
15/12/2019
JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect URL.
Severity CVSS v4.0: Pending analysis
Last modification:
19/12/2019

CVE-2014-3536

Publication date:
15/12/2019
CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration
Severity CVSS v4.0: Pending analysis
Last modification:
19/12/2019

CVE-2014-3699

Publication date:
15/12/2019
eDeploy has RCE via cPickle deserialization of untrusted data
Severity CVSS v4.0: Pending analysis
Last modification:
19/12/2019

CVE-2014-4913

Publication date:
15/12/2019
ZF2014-03 has a potential cross site scripting vector in multiple view helpers
Severity CVSS v4.0: Pending analysis
Last modification:
19/12/2019

CVE-2014-3701

Publication date:
15/12/2019
eDeploy has tmp file race condition flaws
Severity CVSS v4.0: Pending analysis
Last modification:
19/12/2019