Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-7128

Publication date:
04/11/2020
A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-7129

Publication date:
04/11/2020
A remote execution of arbitrary commands vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-28049

Publication date:
04/11/2020
An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection to the X server without providing proper authentication. A local attacker can thus access X server display contents and, for example, intercept keystrokes or access the clipboard. This is caused by a race condition during Xauthority file creation.
Severity CVSS v4.0: Pending analysis
Last modification:
15/10/2024

CVE-2020-8036

Publication date:
04/11/2020
The tok2strbuf() function in tcpdump 4.10.0-PRE-GIT was used by the SOME/IP dissector in an unsafe way.
Severity CVSS v4.0: Pending analysis
Last modification:
25/11/2020

CVE-2020-8037

Publication date:
04/11/2020
The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-22274

Publication date:
04/11/2020
JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.
Severity CVSS v4.0: Pending analysis
Last modification:
12/11/2020

CVE-2020-22273

Publication date:
04/11/2020
Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Settings)
Severity CVSS v4.0: Pending analysis
Last modification:
13/11/2020

CVE-2020-22278

Publication date:
04/11/2020
phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2024

CVE-2020-22277

Publication date:
04/11/2020
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-26167

Publication date:
04/11/2020
In FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any account including an administrator one.
Severity CVSS v4.0: Pending analysis
Last modification:
30/05/2025

CVE-2020-22276

Publication date:
04/11/2020
WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.
Severity CVSS v4.0: Pending analysis
Last modification:
12/11/2020

CVE-2020-22275

Publication date:
04/11/2020
Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, there is no check on this inputs and the codes are executable.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021