Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-19588

Publication date:
11/07/2019
Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control.
Severity CVSS v4.0: Pending analysis
Last modification:
18/07/2019

CVE-2019-10194

Publication date:
11/07/2019
Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could be disclosed in log files (if playbooks are run with -v) or in playbooks stored on Metrics or Bastion hosts.
Severity CVSS v4.0: Pending analysis
Last modification:
01/03/2023

CVE-2019-13564

Publication date:
11/07/2019
XSS exists in Ping Identity Agentless Integration Kit before 1.5.
Severity CVSS v4.0: Pending analysis
Last modification:
30/01/2023

CVE-2019-11268

Publication date:
11/07/2019
Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can extend those reading privileges to all other identity zones and obtain private information on users, clients, and groups in all other identity zones.
Severity CVSS v4.0: Pending analysis
Last modification:
02/10/2020

CVE-2019-10651

Publication date:
11/07/2019
An issue was discovered in the Core Server in Ivanti Endpoint Manager (EPM) 2017.3 before SU7 and 2018.x before 2018.3 SU3, with remote code execution. In other words, the issue affects 2017.3, 2018.1, and 2018.3 installations that lack the April 2019 update.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-13560

Publication date:
11/07/2019
D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to force a blank password via the apply_sec.cgi setup_wizard parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2021

CVE-2019-13563

Publication date:
11/07/2019
D-Link DIR-655 C devices before 3.02B05 BETA03 allow CSRF for the entire management console.
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2021

CVE-2019-13562

Publication date:
11/07/2019
D-Link DIR-655 C devices before 3.02B05 BETA03 allow XSS, as demonstrated by the /www/ping_response.cgi ping_ipaddr parameter, the /www/ping6_response.cgi ping6_ipaddr parameter, and the /www/apply_sec.cgi html_response_return_page parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2019

CVE-2019-13561

Publication date:
11/07/2019
D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to execute arbitrary commands via shell metacharacters in the online_firmware_check.cgi check_fw_url parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-12539

Publication date:
11/07/2019
An issue was discovered in the Purchase component of Zoho ManageEngine ServiceDesk Plus. There is XSS via the SearchN.do search field, a different vulnerability than CVE-2019-12189.
Severity CVSS v4.0: Pending analysis
Last modification:
13/01/2021

CVE-2019-12595

Publication date:
11/07/2019
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
01/03/2023

CVE-2019-12596

Publication date:
11/07/2019
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType.
Severity CVSS v4.0: Pending analysis
Last modification:
01/03/2023