Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2017-17689

Publication date:
16/05/2018
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-11212

Publication date:
16/05/2018
An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2022

CVE-2018-11213

Publication date:
16/05/2018
An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-11214

Publication date:
16/05/2018
An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-4850

Publication date:
16/05/2018
A vulnerability has been identified in SIMATIC S7-400 (incl. F) CPU hardware version 4.0 and below (All versions), SIMATIC S7-400 (incl. F) CPU hardware version 5.0 (All firmware versions
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2018-8014

Publication date:
16/05/2018
The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.
Severity CVSS v4.0: Pending analysis
Last modification:
08/12/2023

CVE-2018-11207

Publication date:
16/05/2018
A division by zero was discovered in H5D__chunk_init in H5Dchunk.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.
Severity CVSS v4.0: Pending analysis
Last modification:
21/03/2019

CVE-2018-11202

Publication date:
16/05/2018
A NULL pointer dereference was discovered in H5S_hyper_make_spans in H5Shyper.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.
Severity CVSS v4.0: Pending analysis
Last modification:
18/06/2018

CVE-2018-11204

Publication date:
16/05/2018
A NULL pointer dereference was discovered in H5O__chunk_deserialize in H5Ocache.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2018

CVE-2018-11203

Publication date:
16/05/2018
A division by zero was discovered in H5D__btree_decode_key in H5Dbtree.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2018

CVE-2018-11205

Publication date:
16/05/2018
A out of bounds read was discovered in H5VM_memcpyvv in H5VM.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2018

CVE-2018-11208

Publication date:
16/05/2018
An issue was discovered in Z-BlogPHP 2.0.0. There is a persistent XSS that allows remote attackers to inject arbitrary web script or HTML into background web site settings via the "copyright information office" field. NOTE: the vendor indicates that the product was not intended to block this type of XSS by a user with the admin privilege
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2024