Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-16103

Publication date:
14/12/2020
Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution. This issue affects: Gallagher Command Centre 8.30 versions prior to 8.30.1236(MR1); 8.20 versions prior to 8.20.1166(MR3); 8.10 versions prior to 8.10.1211(MR5); version 8.00 and prior versions.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2020-16104

Publication date:
14/12/2020
SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit Enterprise Data Interfaces' privilege to execute arbitrary SQL against a third party database if EDI is configured to import data from this database. This issue affects: Gallagher Command Centre 8.30 versions prior to 8.30.1236(MR1); 8.20 versions prior to 8.20.1166(MR3); 8.10 versions prior to 8.10.1211(MR5); 8.00 versions prior to 8.00.1228(MR6); version 7.90 and prior versions.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2020-20136

Publication date:
14/12/2020
QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNameHandling property in Json.NET library.
Severity CVSS v4.0: Pending analysis
Last modification:
15/12/2020

CVE-2020-28857

Publication date:
14/12/2020
OpenAsset Digital Asset Management (DAM) through 12.0.19, does not correctly sanitize user supplied input in multiple parameters and endpoints, allowing for stored cross-site scripting attacks.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2020-28858

Publication date:
14/12/2020
OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the application was intentionally made by the user, allowing for cross-site request forgery attacks on all user functions.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2020-28859

Publication date:
14/12/2020
OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input in multiple parameters and endpoints, allowing for reflected cross-site scripting attacks.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2020-35338

Publication date:
14/12/2020
The Web Administrative Interface in Mobile Viewpoint Wireless Multiplex Terminal (WMT) Playout Server 20.2.8 and earlier has a default account with a password of "pokon."
Severity CVSS v4.0: Pending analysis
Last modification:
15/12/2020

CVE-2020-28856

Publication date:
14/12/2020
OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP address, allowing attackers to spoof it using X-Forwarded-For in the header, by supplying localhost address such as 127.0.0.1, effectively bypassing all IP address based access controls.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2026

CVE-2020-25175

Publication date:
14/12/2020
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
Severity CVSS v4.0: Pending analysis
Last modification:
30/04/2021

CVE-2020-25179

Publication date:
14/12/2020
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2021

CVE-2020-15733

Publication date:
14/12/2020
An Origin Validation Error vulnerability in the SafePay component of Bitdefender Antivirus Plus allows a web resource to misrepresent itself in the URL bar. This issue affects: Bitdefender Antivirus Plus versions prior to 25.0.7.29.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2020-35382

Publication date:
14/12/2020
SQL Injection in Classbooking before 2.4.1 via the username field of a CSV file when adding a new user.
Severity CVSS v4.0: Pending analysis
Last modification:
14/12/2020