Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-3754

Publication date:
03/09/2019
Dell EMC Unity Operating Environment versions prior to 5.0.0.0.5.116, Dell EMC UnityVSA versions prior to 5.0.0.0.5.116 and Dell EMC VNXe3200 versions prior to 3.1.10.9946299 contain a reflected cross-site scripting vulnerability on the cas/logout page. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or Java Script code to Unisphere, which is then reflected back to the victim and executed by the web browser.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2019-14817

Publication date:
03/09/2019
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-14811

Publication date:
03/09/2019
A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-13156

Publication date:
03/09/2019
NDrive(1.2.2).sys in Naver Cloud Explorer has a stack-based buffer overflow, which allows attackers to cause a denial of service when reading data from IOCTL handle.
Severity CVSS v4.0: Pending analysis
Last modification:
08/10/2020

CVE-2019-10197

Publication date:
03/09/2019
A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-15873

Publication date:
03/09/2019
The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php request with the action=pm_template_preview&html=
Severity CVSS v4.0: Pending analysis
Last modification:
24/01/2022

CVE-2019-15872

Publication date:
03/09/2019
The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings.
Severity CVSS v4.0: Pending analysis
Last modification:
05/09/2019

CVE-2019-15871

Publication date:
03/09/2019
The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-15867

Publication date:
03/09/2019
The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, after a Subscriber calls a certain AJAX action.
Severity CVSS v4.0: Pending analysis
Last modification:
06/09/2019

CVE-2019-15865

Publication date:
03/09/2019
The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has CSRF.
Severity CVSS v4.0: Pending analysis
Last modification:
03/09/2019

CVE-2019-15869

Publication date:
03/09/2019
The JobCareer theme before 2.5.1 for WordPress has stored XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
03/09/2019

CVE-2019-15870

Publication date:
03/09/2019
The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field.
Severity CVSS v4.0: Pending analysis
Last modification:
20/03/2025