Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2017-15030

Publication date:
23/05/2019
Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
Severity CVSS v4.0: Pending analysis
Last modification:
23/05/2019

CVE-2017-5210

Publication date:
23/05/2019
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Information Exposure.
Severity CVSS v4.0: Pending analysis
Last modification:
23/05/2019

CVE-2017-5211

Publication date:
23/05/2019
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.
Severity CVSS v4.0: Pending analysis
Last modification:
23/05/2019

CVE-2017-15029

Publication date:
23/05/2019
Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.
Severity CVSS v4.0: Pending analysis
Last modification:
23/05/2019

CVE-2017-17060

Publication date:
23/05/2019
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Insecure Permissions.
Severity CVSS v4.0: Pending analysis
Last modification:
23/05/2019

CVE-2019-9949

Publication date:
23/05/2019
Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 before firmware 2.31.183 are affected by a code execution (as root, starting from a low-privilege user session) vulnerability. The cgi-bin/webfile_mgr.cgi file allows arbitrary file write by abusing symlinks. Specifically, this occurs by uploading a tar archive that contains a symbolic link, then uploading another archive that writes a file to the link using the "cgi_untar" command. Other commands might also be susceptible. Code can be executed because the "name" parameter passed to the cgi_unzip command is not sanitized.
Severity CVSS v4.0: Pending analysis
Last modification:
29/05/2019

CVE-2019-0201

Publication date:
23/05/2019
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is used for user authentication. As a consequence, if Digest Authentication is in use, the unsalted hash value will be disclosed by getACL() request for unauthenticated or unprivileged users.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-4039

Publication date:
23/05/2019
IBM WebSphere MQ 8.0.0.0 through 8.0.0.9 and 9.0.0.0 through 9.1.1 could allow a local attacker to cause a denial of service within the error log reporting system. IBM X-Force ID: 156163.
Severity CVSS v4.0: Pending analysis
Last modification:
03/12/2022

CVE-2019-4078

Publication date:
23/05/2019
IBM WebSphere MQ 8.0.0.0 through 8.0.0.9 and 9.0.0.0 through 9.1.1 could allow a local non privileged user to execute code as an administrator due to incorrect permissions set on MQ installation directories. IBM X-Force ID: 157190.
Severity CVSS v4.0: Pending analysis
Last modification:
09/12/2022

CVE-2019-12297

Publication date:
23/05/2019
An issue was discovered in scopd on Motorola routers CX2 1.01 and M2 1.01. There is a Use of an Externally Controlled Format String, reachable via TCP port 8010 or UDP port 8080.
Severity CVSS v4.0: Pending analysis
Last modification:
24/05/2019

CVE-2018-15664

Publication date:
23/05/2019
In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Traversal, giving attackers arbitrary read-write access to the host filesystem with root privileges, because daemon/archive.go does not do archive operations on a frozen filesystem (or from within a chroot).
Severity CVSS v4.0: Pending analysis
Last modification:
25/06/2019

CVE-2019-12298

Publication date:
23/05/2019
Leanify 0.4.3 allows remote attackers to trigger an out-of-bounds write (1024 bytes) via a modified input file.
Severity CVSS v4.0: Pending analysis
Last modification:
23/05/2019