Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-14783

Publication date:
10/08/2018
NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. A cross-site request forgery condition can occur, allowing an attacker to change passwords of the device remotely.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2018-14784

Publication date:
10/08/2018
NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device is vulnerable to several cross-site scripting attacks, allowing a remote attacker to run arbitrary code on the device.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2018-14785

Publication date:
10/08/2018
NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The directory of the device is listed openly without authentication.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2018-10622

Publication date:
10/08/2018
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication and encryption of local data at rest.
Severity CVSS v4.0: Pending analysis
Last modification:
22/05/2025

CVE-2018-10626

Publication date:
10/08/2018
Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired implantable cardiac device information can potentially upload invalid data to the Medtronic CareLink network.
Severity CVSS v4.0: Pending analysis
Last modification:
22/05/2025

CVE-2018-15190

Publication date:
10/08/2018
PHP Scripts Mall hotel-booking-script 2.0.4 allows XSS via the First Name, Last Name, or Address field.
Severity CVSS v4.0: Pending analysis
Last modification:
06/10/2018

CVE-2018-15191

Publication date:
10/08/2018
PHP Scripts Mall hotel-booking-script 2.0.4 allows remote attackers to cause a denial of service via crafted JavaScript code in the First Name, Last Name, or Address field.
Severity CVSS v4.0: Pending analysis
Last modification:
06/10/2018

CVE-2018-14837

Publication date:
10/08/2018
Wolf CMS 0.8.3.1 has XSS in the Snippets tab, as demonstrated by a ?/admin/snippet/edit/1 URI.
Severity CVSS v4.0: Pending analysis
Last modification:
05/10/2018

CVE-2018-14503

Publication date:
10/08/2018
Cross-site scripting (XSS) vulnerability in intervalCheck.jsp in Coremail XT 3.0 allows remote attackers to inject arbitrary web script or HTML via the sid parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
05/10/2018

CVE-2018-14028

Publication date:
10/08/2018
In WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files to be uploaded. Once a PHP file is uploaded, the plugin extraction fails, but the PHP file remains in a predictable wp-content/uploads location, allowing for an attacker to then execute the file. This represents a security risk in limited scenarios where an attacker (who does have the required capabilities for plugin uploads) cannot simply place arbitrary PHP code into a valid plugin ZIP file and upload that plugin, because a machine's wp-content/plugins directory permissions were set up to block all new plugins.
Severity CVSS v4.0: Pending analysis
Last modification:
10/10/2018

CVE-2018-11492

Publication date:
10/08/2018
ASUS HG100 devices allow denial of service via an IPv4 packet flood.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-7754

Publication date:
10/08/2018
The aoedisk_debugfs_show function in drivers/block/aoe/aoeblk.c in the Linux kernel through 4.16.4rc4 allows local users to obtain sensitive address information by reading "ffree: " lines in a debugfs file.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020