Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-6862

Publication date:
12/02/2018
Cross Site Scripting (XSS) exists in PHP Scripts Mall Bitcoin MLM Software 1.0.2 via a profile field.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-6863

Publication date:
12/02/2018
SQL Injection exists in PHP Scripts Mall Select Your College Script 2.0.2 via a Login Parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-6864

Publication date:
12/02/2018
Cross Site Scripting (XSS) exists in PHP Scripts Mall Multi religion Responsive Matrimonial 4.7.2 via a user profile update parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-6880

Publication date:
12/02/2018
EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/connect.php.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-6881

Publication date:
12/02/2018
EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-6888

Publication date:
12/02/2018
An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: using a forged HTTP request, a malicious user can lead a user to unknowingly create / delete or modify a user account due to the lack of an anti-CSRF token.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-6889

Publication date:
12/02/2018
An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the web cache or perform advanced password reset attacks or even trigger arbitrary user re-direction.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-6912

Publication date:
12/02/2018
The decode_plane function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read) via a crafted AVI file.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-6892

Publication date:
11/02/2018
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sync" client application listening on port 8888 can send a malicious payload causing a buffer overflow condition. This will result in an attacker controlling the program's execution flow and allowing arbitrary code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-18174

Publication date:
11/02/2018
In the Linux kernel before 4.7, the amd_gpio_remove function in drivers/pinctrl/pinctrl-amd.c calls the pinctrl_unregister function, leading to a double free.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-6891

Publication date:
11/02/2018
Bookly #1 WordPress Booking Plugin Lite before 14.5 has XSS via a jQuery.ajax request to ng-payment_details_dialog.js.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-1000061

Publication date:
09/02/2018
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023