Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2015-9258

Publication date:
31/03/2018
In Docker Notary before 0.1, gotuf/signed/verify.go has a Signature Algorithm Not Matched to Key vulnerability. Because an attacker controls the field specifying the signature algorithm, they might (for example) be able to forge a signature by forcing a misinterpretation of an RSA-PSS key as Ed25519 elliptic-curve data.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2015-9259

Publication date:
31/03/2018
In Docker Notary before 0.1, the checkRoot function in gotuf/client/client.go does not check expiry of root.json files, despite a comment stating that it does. Even if a user creates a new root.json file after a key compromise, an attacker can produce update files referring to an old root.json file.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-9159

Publication date:
31/03/2018
In Spark before 2.7.2, a remote attacker can read unintended static files via various representations of absolute or relative pathnames, as demonstrated by file: URLs and directory traversal sequences. NOTE: this product is unrelated to Ignite Realtime Spark.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-9160

Publication date:
31/03/2018
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-18255

Publication date:
31/03/2018
The perf_cpu_time_max_percent_handler function in kernel/events/core.c in the Linux kernel before 4.11 allows local users to cause a denial of service (integer overflow) or possibly have unspecified other impact via a large value, as demonstrated by an incorrect sample-rate calculation.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-7566

Publication date:
30/03/2018
The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-17766

Publication date:
30/03/2018
In wma_peer_info_event_handler() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-03, the value of num_peers received from firmware is not properly validated so that an integer overflow vulnerability in the size of a buffer allocation may potentially lead to a buffer overflow.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-17769

Publication date:
30/03/2018
Information leakage in Android for MSM, Firefox OS for MSM, and QRD Android can occur in the audio driver.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2017-17771

Publication date:
30/03/2018
In msm_isp_prepare_v4l2_buf in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-02-12, an array out of bounds can occur.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-1232

Publication date:
30/03/2018
RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by a stack-based buffer overflow which may occur when handling certain malicious web cookies that have invalid formats. The attacker could exploit this vulnerability to crash the authentication agent and cause a denial-of-service situation.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-1233

Publication date:
30/03/2018
RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are affected by a cross-site scripting vulnerability. The attackers could potentially exploit this vulnerability to execute arbitrary HTML or JavaScript code in the user's browser session in the context of the affected website.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026

CVE-2018-1234

Publication date:
30/03/2018
RSA Authentication Agent version 8.0.1 and earlier for Web for IIS is affected by a problem where access control list (ACL) permissions on a Windows Named Pipe were not sufficient to prevent access by unauthorized users. The attacker with local access to the system can exploit this vulnerability to read configuration properties for the authentication agent.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2026