Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-6862

Publication date:
12/02/2018
Cross Site Scripting (XSS) exists in PHP Scripts Mall Bitcoin MLM Software 1.0.2 via a profile field.
Severity CVSS v4.0: Pending analysis
Last modification:
26/02/2018

CVE-2018-6864

Publication date:
12/02/2018
Cross Site Scripting (XSS) exists in PHP Scripts Mall Multi religion Responsive Matrimonial 4.7.2 via a user profile update parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
26/02/2018

CVE-2018-6889

Publication date:
12/02/2018
An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the web cache or perform advanced password reset attacks or even trigger arbitrary user re-direction.
Severity CVSS v4.0: Pending analysis
Last modification:
06/03/2018

CVE-2018-6888

Publication date:
12/02/2018
An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: using a forged HTTP request, a malicious user can lead a user to unknowingly create / delete or modify a user account due to the lack of an anti-CSRF token.
Severity CVSS v4.0: Pending analysis
Last modification:
06/03/2018

CVE-2018-6861

Publication date:
12/02/2018
Cross Site Scripting (XSS) exists in PHP Scripts Mall Lawyer Search Script 1.0.2 via a profile update parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
11/03/2020

CVE-2018-6860

Publication date:
12/02/2018
Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script 2.0.2 via a profile picture.
Severity CVSS v4.0: Pending analysis
Last modification:
11/03/2020

CVE-2018-6858

Publication date:
12/02/2018
Cross Site Scripting (XSS) exists in PHP Scripts Mall Facebook Clone Script.
Severity CVSS v4.0: Pending analysis
Last modification:
11/03/2020

CVE-2018-6845

Publication date:
12/02/2018
PHP Scripts Mall Multi Language Olx Clone Script 2.0.6 has XSS via the Leave Comment field.
Severity CVSS v4.0: Pending analysis
Last modification:
11/03/2020

CVE-2018-6880

Publication date:
12/02/2018
EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/connect.php.
Severity CVSS v4.0: Pending analysis
Last modification:
19/02/2022

CVE-2018-6881

Publication date:
12/02/2018
EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php.
Severity CVSS v4.0: Pending analysis
Last modification:
19/02/2022

CVE-2018-6912

Publication date:
12/02/2018
The decode_plane function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read) via a crafted AVI file.
Severity CVSS v4.0: Pending analysis
Last modification:
30/03/2020

CVE-2017-18174

Publication date:
11/02/2018
In the Linux kernel before 4.7, the amd_gpio_remove function in drivers/pinctrl/pinctrl-amd.c calls the pinctrl_unregister function, leading to a double free.
Severity CVSS v4.0: Pending analysis
Last modification:
21/12/2018