Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-9307

Publication date:
04/04/2018
dsmall v20180320 allows XSS via the pdr_sn parameter to public/index.php/home/predeposit/index.html.
Severity CVSS v4.0: Pending analysis
Last modification:
18/04/2018

CVE-2018-9304

Publication date:
04/04/2018
In Exiv2 0.26, a divide by zero in BigTiffImage::printIFD in bigtiffimage.cpp could result in denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
27/02/2019

CVE-2018-9303

Publication date:
04/04/2018
In Exiv2 0.26, an assertion failure in BigTiffImage::readData in bigtiffimage.cpp results in an abort.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-9305

Publication date:
04/04/2018
In Exiv2 0.26, an out-of-bounds read in IptcData::printStructure in iptc.c could result in a crash or information leak, related to the "== 0x1c" case.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2019

CVE-2018-1081

Publication date:
04/04/2018
A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions. Unauthenticated users can trigger custom messages to admin via paypal enrol script. Paypal IPN callback script should only send error emails to admin after request origin was verified, otherwise admin email can be spammed.
Severity CVSS v4.0: Pending analysis
Last modification:
28/08/2020

CVE-2018-1082

Publication date:
04/04/2018
A flaw was found in Moodle 3.4 to 3.4.1, and 3.3 to 3.3.4. If a user account using OAuth2 authentication method was once confirmed but later suspended, the user could still login to the site.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2018-1097

Publication date:
04/04/2018
A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the username and password used to connect to the compute resource.
Severity CVSS v4.0: Pending analysis
Last modification:
13/02/2023

CVE-2018-1002150

Publication date:
04/04/2018
Koji version 1.12, 1.13, 1.14 and 1.15 contain an incorrect access control vulnerability resulting in arbitrary filesystem read/write access. This vulnerability has been fixed in versions 1.12.1, 1.13.1, 1.14.1 and 1.15.1.
Severity CVSS v4.0: Pending analysis
Last modification:
21/12/2022

CVE-2018-8719

Publication date:
04/04/2018
An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these files are indexed by Google and allows for attackers to possibly find sensitive information.
Severity CVSS v4.0: Pending analysis
Last modification:
11/05/2018

CVE-2018-9034

Publication date:
04/04/2018
Cross-site scripting (XSS) vulnerability in lib/interface.php of the Relevanssi plugin 4.0.4 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the tab GET parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
09/05/2018

CVE-2018-9115

Publication date:
04/04/2018
Systematic SitaWare 6.4 SP2 does not validate input from other sources sufficiently. e.g., information utilizing the NVG interface. An attacker can freeze the Situational Layer, which means that the Situational Picture is no longer updated. Unfortunately, the user cannot notice until he tries to work with that layer.
Severity CVSS v4.0: Pending analysis
Last modification:
22/05/2018

CVE-2018-9126

Publication date:
04/04/2018
The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and consequently discover database credentials, via the /GetCSS.ashx/?CP=%2fweb.config URI.
Severity CVSS v4.0: Pending analysis
Last modification:
22/05/2018