Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-18966

Publication date:
06/11/2018
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but Internet Explorer render HTML elements in a .eml file.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2018-17905

Publication date:
05/11/2018
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with a specific byte, memory corruption may occur within a specific object.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2018-17907

Publication date:
05/11/2018
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with the value of an offset, an attacker can force the application to read a value outside of an array.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2018-17909

Publication date:
05/11/2018
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, the application fails to check if it is referencing freed memory, which may allow an attacker to execute code under the context of the application.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2018-17913

Publication date:
05/11/2018
A type confusion vulnerability exists when processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, which may allow an attacker to execute code in the context of the application.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2018-13396

Publication date:
05/11/2018
There was an argument injection vulnerability in Sourcetree for macOS from version 1.0b2 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system.
Severity CVSS v4.0: Pending analysis
Last modification:
11/05/2020

CVE-2018-13397

Publication date:
05/11/2018
There was an argument injection vulnerability in Sourcetree for Windows from version 0.5.1.0 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-18957

Publication date:
05/11/2018
An issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_publisher.c.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2018-18956

Publication date:
05/11/2018
The ProcessMimeEntity function in util-decode-mime.c in Suricata 4.x before 4.0.6 allows remote attackers to cause a denial of service (segfault and daemon crash) via crafted input to the SMTP parser, as exploited in the wild in November 2018.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2018-18820

Publication date:
05/11/2018
A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enabled, then any malicious HTTP client can send a request for that specific resource including a crafted header, leading to denial of service and potentially remote code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
23/01/2019

CVE-2018-9208

Publication date:
05/11/2018
Unauthenticated arbitrary file upload vulnerability in jQuery Picture Cut
Severity CVSS v4.0: Pending analysis
Last modification:
10/12/2018

CVE-2018-18933

Publication date:
05/11/2018
The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Read Access Violation near NULL starting at FoxitReader!safe_vsnprintf+0x00000000002c4330" issue.
Severity CVSS v4.0: Pending analysis
Last modification:
30/01/2019