Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-9928

Publication date:
24/04/2019
GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-7214

Publication date:
24/04/2019
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default after applying the Build 6985 patch.
Severity CVSS v4.0: Pending analysis
Last modification:
11/07/2023

CVE-2019-7212

Publication date:
24/04/2019
SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users’ emails and file attachments. It was also possible to interact with mailing lists.
Severity CVSS v4.0: Pending analysis
Last modification:
10/02/2020

CVE-2019-7211

Publication date:
24/04/2019
SmarterTools SmarterMail 16.x before build 6995 has stored XSS. JavaScript code could be executed on the application by opening a malicious email or when viewing a malicious file attachment.
Severity CVSS v4.0: Pending analysis
Last modification:
29/04/2019

CVE-2019-11032

Publication date:
24/04/2019
In EasyToRecruit (E2R) before 2.11, the upload feature and the Candidate Profile Management feature are prone to Cross Site Scripting (XSS) injection in multiple locations.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2018-13443

Publication date:
24/04/2019
EOS.IO jit-wasm 4.1 has a heap-based buffer overflow via a crafted wast file.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-10239

Publication date:
24/04/2019
Robotronic RunAsSpc 3.7.0.0 protects stored credentials insufficiently, which allows locally authenticated attackers (under the same user context) to obtain cleartext credentials of the stored account.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-11081

Publication date:
24/04/2019
A default username and password in Dentsply Sirona Sidexis 4.3.1 and earlier allows an attacker to gain administrative access to the application server.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-9724

Publication date:
24/04/2019
aquaverde Aquarius CMS through 4.3.5 allows Information Exposure through Log Files because of an error in the Log-File writer component.
Severity CVSS v4.0: Pending analysis
Last modification:
29/04/2019

CVE-2019-11498

Publication date:
24/04/2019
WavpackSetConfiguration64 in pack_utils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditional jump or move depends on uninitialised value" condition, which might allow attackers to cause a denial of service (application crash) via a DFF file that lacks valid sample-rate data.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-11490

Publication date:
24/04/2019
An issue was discovered in Npcap 0.992. Sending a malformed .pcap file with the loopback adapter using either pcap_sendqueue_queue() or pcap_sendqueue_transmit() results in kernel pool corruption. This could lead to arbitrary code executing inside the Windows kernel and allow escalation of privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
29/04/2019

CVE-2019-11486

Publication date:
23/04/2019
The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 has multiple race conditions.
Severity CVSS v4.0: Pending analysis
Last modification:
05/10/2023