Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-1000851

Publication date:
20/12/2018
Copay Bitcoin Wallet version 5.01 to 5.1.0 included. contains a Other/Unknown vulnerability in wallet private key storage that can result in Users' private key can be compromised. . This attack appear to be exploitable via Affected version run the malicious code at startup . This vulnerability appears to have been fixed in 5.2.0 and later .
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2018-1000852

Publication date:
20/12/2018
FreeRDP FreeRDP 2.0.0-rc3 released version before commit 205c612820dac644d665b5bb1cdf437dc5ca01e3 contains a Other/Unknown vulnerability in channels/drdynvc/client/drdynvc_main.c, drdynvc_process_capability_request that can result in The RDP server can read the client's memory.. This attack appear to be exploitable via RDPClient must connect the rdp server with echo option. This vulnerability appears to have been fixed in after commit 205c612820dac644d665b5bb1cdf437dc5ca01e3.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2018-1000826

Publication date:
20/12/2018
Microweber version
Severity CVSS v4.0: Pending analysis
Last modification:
15/01/2019

CVE-2018-1000827

Publication date:
20/12/2018
Ubilling version
Severity CVSS v4.0: Pending analysis
Last modification:
01/02/2019

CVE-2018-1000839

Publication date:
20/12/2018
LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This attack appear to be exploitable via Uploading a PHP file with image MIME type.
Severity CVSS v4.0: Pending analysis
Last modification:
01/02/2019

CVE-2018-1000841

Publication date:
20/12/2018
Zend.To version Prior to 5.15-1 contains a Cross Site Scripting (XSS) vulnerability in The verify.php page that can result in An attacker could execute arbitrary Javascript code in the context of the victim's browser.. This attack appear to be exploitable via HTTP POST request. This vulnerability appears to have been fixed in 5.16-1 Beta.
Severity CVSS v4.0: Pending analysis
Last modification:
04/02/2019

CVE-2018-1000833

Publication date:
20/12/2018
ZoneMinder version
Severity CVSS v4.0: Pending analysis
Last modification:
06/02/2019

CVE-2018-1000840

Publication date:
20/12/2018
Processing Foundation Processing version 3.4 and earlier contains a XML External Entity (XXE) vulnerability in loadXML() function that can result in An attacker can read arbitrary files and exfiltrate their contents via HTTP requests. This attack appear to be exploitable via The victim must use Processing to parse a crafted XML document.
Severity CVSS v4.0: Pending analysis
Last modification:
07/02/2019

CVE-2018-1000829

Publication date:
20/12/2018
Anyplace version before commit 80359b4 contains a XML External Entity (XXE) vulnerability in Man in the middle on map API call that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This vulnerability appears to have been fixed in after commit 80359b4.
Severity CVSS v4.0: Pending analysis
Last modification:
07/02/2019

CVE-2018-1000836

Publication date:
20/12/2018
bw-calendar-engine version
Severity CVSS v4.0: Pending analysis
Last modification:
07/02/2019

CVE-2018-1000838

Publication date:
20/12/2018
autopsy version
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2019

CVE-2018-1000834

Publication date:
20/12/2018
runelite version
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2019