Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-11712

Publication date:
12/04/2020
Open Upload through 0.4.3 allows XSS via index.php?action=u and the filename field.
Severity CVSS v4.0: Pending analysis
Last modification:
13/04/2020

CVE-2020-11709

Publication date:
12/04/2020
cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, which creates possibilities for CRLF injection and HTTP response splitting in some specific contexts.
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2025

CVE-2020-11707

Publication date:
12/04/2020
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. It doesn't enforce permission over Windows Symlinks or Junctions. As a result, a low-privileged user (non-admin) can craft a Junction Link in a directory he has full control of, breaking out of the sandbox.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-11708

Publication date:
12/04/2020
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. Privilege escalation can occur via the /ajax/SetUserInfo messages parameter because of the EXECUTE() feature, which is for executing programs when certain events are triggered.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-11706

Publication date:
12/04/2020
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Interface allows CSRF for actions such as: Change any username and password, admin ones included; Create/Delete users; Enable/Disable Services; Set a rogue update proxy; and Shutdown the server.
Severity CVSS v4.0: Pending analysis
Last modification:
13/04/2020

CVE-2020-11705

Publication date:
12/04/2020
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/ImportCertificate allows an attacker to load an arbitrary certificate in .pfx format or overwrite arbitrary files via the fileName parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
13/04/2020

CVE-2020-11704

Publication date:
12/04/2020
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Web Interface has Multiple Stored and Reflected XSS. GetInheritedProperties is Reflected via the groups parameter. GetUserInfo is Reflected via POST data. SetUserInfo is Stored via the general parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
13/04/2020

CVE-2020-11701

Publication date:
12/04/2020
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. CSRF exists in the User Web Interface, as demonstrated by granting filesystem access to the public for uploading and deleting files and directories.
Severity CVSS v4.0: Pending analysis
Last modification:
13/04/2020

CVE-2020-11702

Publication date:
12/04/2020
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The User Web Interface has Multiple Stored and Reflected XSS issues. Collaborate is Reflected via the filename parameter. Collaborate is Stored via the displayname parameter. Deletemultiple is Reflected via the files parameter. Share is Reflected via the target parameter. Share is Stored via the displayname parameter. Waitedit is Reflected via the Host header.
Severity CVSS v4.0: Pending analysis
Last modification:
13/04/2020

CVE-2020-11703

Publication date:
12/04/2020
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/GetInheritedProperties allows HTTP Response Splitting via the language parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
13/04/2020

CVE-2020-11647

Publication date:
10/04/2020
In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-11694

Publication date:
10/04/2020
In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3.
Severity CVSS v4.0: Pending analysis
Last modification:
06/04/2022