Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-14445

Publication date:
20/07/2018
In Bento4 v1.5.1-624, AP4_File::ParseStream in Ap4File.cpp allows remote attackers to cause a denial of service (infinite loop) via a crafted MP4 file.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-14446

Publication date:
20/07/2018
MP4Integer32Property::Read in atom_avcC.cpp in MP4v2 2.1.0 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted MP4 file.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2018-14442

Publication date:
20/07/2018
Foxit Reader before 9.2 and PhantomPDF before 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4smlocs.
Severity CVSS v4.0: Pending analysis
Last modification:
17/09/2018

CVE-2016-10727

Publication date:
20/07/2018
camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. The server code was intended to report an error and not proceed, but the code was written incorrectly.
Severity CVSS v4.0: Pending analysis
Last modification:
18/09/2018

CVE-2018-8018

Publication date:
20/07/2018
In Apache Ignite before 2.4.8 and 2.5.x before 2.5.3, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulnerability can be exploited if the one sends a specially prepared form of a serialized object to GridClientJdkMarshaller deserialization endpoint.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2018-14422

Publication date:
20/07/2018
blog/index.php in SansCMS 0.7 has XSS via the q parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
17/09/2018

CVE-2018-14418

Publication date:
20/07/2018
In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
Severity CVSS v4.0: Pending analysis
Last modification:
17/09/2018

CVE-2018-14415

Publication date:
20/07/2018
An issue was discovered in idreamsoft iCMS before 7.0.10. XSS exists via the fourth and fifth input elements on the admincp.php?app=prop&do=add screen.
Severity CVSS v4.0: Pending analysis
Last modification:
17/09/2018

CVE-2018-14420

Publication date:
20/07/2018
MetInfo 6.0.0 allows a CSRF attack to add a user account via a doaddsave action to admin/index.php, as demonstrated by an admin/index.php?anyid=47&n=admin&c=admin_admin&a=doaddsave URI.
Severity CVSS v4.0: Pending analysis
Last modification:
14/09/2018

CVE-2018-14419

Publication date:
20/07/2018
MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page.
Severity CVSS v4.0: Pending analysis
Last modification:
14/09/2018

CVE-2018-14421

Publication date:
20/07/2018
SeaCMS v6.61 allows Remote Code execution by placing PHP code in a movie picture address (aka v_pic) to /admin/admin_video.php (aka /backend/admin_video.php). The code is executed by visiting /details/index.php. This can also be exploited through CSRF.
Severity CVSS v4.0: Pending analysis
Last modification:
14/09/2018

CVE-2018-14438

Publication date:
20/07/2018
In Wireshark through 2.6.2, the create_app_running_mutex function in wsutil/file_util.c calls SetSecurityDescriptorDacl to set a NULL DACL, which allows attackers to modify the access control arbitrarily.
Severity CVSS v4.0: Pending analysis
Last modification:
17/09/2018