Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-3477

Publication date:
07/06/2019
Micro Focus Solution Business Manager versions prior to 11.4.2 is susceptible to open redirect.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2018-19461

Publication date:
07/06/2019
admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2018-19999

Publication date:
07/06/2019
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit this vulnerability, an attacker must have local access the the host running Serv-U, and a Serv-U administrator have an active management console session.
Severity CVSS v4.0: Pending analysis
Last modification:
10/06/2019

CVE-2018-19465

Publication date:
07/06/2019
Maccms through 8.0 allows XSS via the site_keywords field to index.php?m=system-config because of tpl/module/system.php and tpl/html/system_config.html, related to template/paody/html/vod_index.html.
Severity CVSS v4.0: Pending analysis
Last modification:
10/06/2019

CVE-2018-19451

Publication date:
07/06/2019
A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when using the Open File action on a Field. An attacker can leverage this to gain remote code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
10/06/2019

CVE-2018-19452

Publication date:
07/06/2019
A use after free in the TextBox field Mouse Enter action in IReader_ContentProvider can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031. An attacker can leverage this to gain remote code execution. Relative to CVE-2018-19444, this has a different free location and requires different JavaScript code for exploitation.
Severity CVSS v4.0: Pending analysis
Last modification:
10/06/2019

CVE-2018-19800

Publication date:
07/06/2019
aubio v0.4.0 to v0.4.8 has a Buffer Overflow in new_aubio_tempo.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2018-19801

Publication date:
07/06/2019
aubio v0.4.0 to v0.4.8 has a NULL pointer dereference in new_aubio_filterbank via invalid n_filters.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2018-19802

Publication date:
07/06/2019
aubio v0.4.0 to v0.4.8 has a new_aubio_onset NULL pointer dereference.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2018-19462

Publication date:
07/06/2019
admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses a .php filename in a SELECT INTO OUTFILE statement to admin/admin.php.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2018-19860

Publication date:
07/06/2019
Broadcom firmware before summer 2014 on Nexus 5 BCM4335C0 2012-12-11, Raspberry Pi 3 BCM43438A1 2014-06-02, and unspecifed other devices does not properly restrict LMP commnds and executes certain memory contents upon receiving an LMP command, as demonstrated by executing an HCI command.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2018-20523

Publication date:
07/06/2019
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request.
Severity CVSS v4.0: Pending analysis
Last modification:
19/04/2022