Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-14522

Publication date:
23/07/2018
An issue was discovered in aubio 0.4.6. A SEGV signal can occur in aubio_pitch_set_unit in pitch/pitch.c, as demonstrated by aubionotes.
Severity CVSS v4.0: Pending analysis
Last modification:
17/04/2019

CVE-2018-14523

Publication date:
23/07/2018
An issue was discovered in aubio 0.4.6. A buffer over-read can occur in new_aubio_pitchyinfft in pitch/pitchyinfft.c, as demonstrated by aubionotes.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-14532

Publication date:
23/07/2018
An issue was discovered in Bento4 1.5.1-624. There is a heap-based buffer over-read in AP4_Mpeg2TsVideoSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp after a call from Mp42Hls.cpp, a related issue to CVE-2018-13846.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-14549

Publication date:
23/07/2018
An issue has been found in libwav through 2017-04-20. It is a SEGV in the function wav_write in libwav.c.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-14512

Publication date:
23/07/2018
An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[nickname] parameter to the index.php?m=core&f=set&v=sendmail URI. When the administrator accesses the "system settings - mail server" screen, the XSS payload is triggered.
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2025

CVE-2018-14551

Publication date:
23/07/2018
The ReadMATImageV4 function in coders/mat.c in ImageMagick 7.0.8-7 uses an uninitialized variable, leading to memory corruption.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2018-14505

Publication date:
22/07/2018
mitmweb in mitmproxy v4.0.3 allows DNS Rebinding attacks, related to tools/web/app.py.
Severity CVSS v4.0: Pending analysis
Last modification:
18/09/2018

CVE-2018-14501

Publication date:
22/07/2018
manager/admin_ajax.php in joyplus-cms 1.6.0 has SQL Injection, as demonstrated by crafted POST data beginning with an "m_id=1 AND SLEEP(5)" substring.
Severity CVSS v4.0: Pending analysis
Last modification:
17/09/2018

CVE-2018-14500

Publication date:
22/07/2018
joyplus-cms 1.6.0 has XSS via the manager/collect/collect_vod_zhuiju.php keyword parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
18/02/2020

CVE-2018-14492

Publication date:
21/07/2018
Tenda AC7 through V15.03.06.44_CN, AC9 through V15.03.05.19(6318)_CN, and AC10 through V15.03.06.23_CN devices have a Stack-based Buffer Overflow via a long limitSpeed or limitSpeedup parameter to an unspecified /goform URI.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2018-3770

Publication date:
20/07/2018
A path traversal exists in markdown-pdf version
Severity CVSS v4.0: Pending analysis
Last modification:
28/02/2023

CVE-2018-3771

Publication date:
20/07/2018
An XSS in statics-server
Severity CVSS v4.0: Pending analysis
Last modification:
30/01/2023