Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2014-2711

Publication date:
14/04/2014
Cross-site scripting (XSS) vulnerability in J-Web in Juniper Junos before 11.4R11, 11.4X27 before 11.4X27.62 (BBE), 12.1 before 12.1R9, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, 12.2 before 12.2R7, 12.3 before 12.3R6, 13.1 before 13.1R4, 13.2 before 13.2R3, and 13.3 before 13.3R1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Severity CVSS v4.0: Pending analysis
Last modification:
12/04/2025

CVE-2014-0128

Publication date:
14/04/2014
Squid 3.1 before 3.3.12 and 3.4 before 3.4.4, when SSL-Bump is enabled, allows remote attackers to cause a denial of service (assertion failure) via a crafted range request, related to state management.
Severity CVSS v4.0: Pending analysis
Last modification:
12/04/2025

CVE-2014-0159

Publication date:
14/04/2014
Buffer overflow in the GetStatistics64 remote procedure call (RPC) in OpenAFS 1.4.8 before 1.6.7 allows remote attackers to cause a denial of service (crash) via a crafted statsVersion argument.
Severity CVSS v4.0: Pending analysis
Last modification:
12/04/2025

CVE-2013-2828

Publication date:
12/04/2014
The DNP Master Driver in the OSIsoft PI Interface before 3.1.2.54 for DNP3 allows physically proximate attackers to cause a denial of service (interface shutdown) via crafted input over a serial line.
Severity CVSS v4.0: Pending analysis
Last modification:
12/04/2025

CVE-2014-0347

Publication date:
12/04/2014
The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix 31, and Web Security Gateway Anywhere 7.7.3 before Hotfix 31 allows remote authenticated users to read cleartext passwords by replacing type="password" with type="text" in an INPUT element in the (1) Log Database or (2) User Directories component.
Severity CVSS v4.0: Pending analysis
Last modification:
12/04/2025

CVE-2014-0770

Publication date:
12/04/2014
By providing an overly long string to the UserName parameter, an <br /> attacker may be able to overflow the static stack buffer. The attacker <br /> may then execute code on the target device remotely.
Severity CVSS v4.0: Pending analysis
Last modification:
19/09/2025

CVE-2014-0771

Publication date:
12/04/2014
The BWOCXRUN.BwocxrunCtrl.1 control contains a method named <br /> “OpenUrlToBuffer.” This method takes a URL as a parameter and returns <br /> its contents to the caller in JavaScript. The URLs are accessed in the <br /> security context of the current browser session. The control does not <br /> perform any URL validation and allows “file://” URLs that access the <br /> local disk.<br /> <br /> <br /> The method can be used to open a URL (including file URLs) and read <br /> file URLs through JavaScript. This method could also be used to reach <br /> any arbitrary URL to which the browser has access.
Severity CVSS v4.0: Pending analysis
Last modification:
19/09/2025

CVE-2014-0772

Publication date:
12/04/2014
The BWOCXRUN.BwocxrunCtrl.1 control contains a method named <br /> OpenUrlToBufferTimeout. This method takes a URL as a parameter and <br /> returns its contents to the caller in JavaScript. The URLs are accessed <br /> in the security context of the current browser session. The control does<br /> not perform any URL validation and allows file:// URLs that access the <br /> local disk.<br /> <br /> <br /> The method can be used to open a URL (including file URLs) and read <br /> the URLs through JavaScript. This method could also be used to reach any<br /> arbitrary URL to which the browser has access.
Severity CVSS v4.0: Pending analysis
Last modification:
19/09/2025

CVE-2014-0349

Publication date:
12/04/2014
Multiple unspecified vulnerabilities in J2k-Codec allow remote attackers to execute arbitrary code via a crafted JPEG 2000 file.
Severity CVSS v4.0: Pending analysis
Last modification:
12/04/2025

CVE-2014-0773

Publication date:
12/04/2014
The BWOCXRUN.BwocxrunCtrl.1 control contains a method named <br /> “CreateProcess.” This method contains validation to ensure an attacker <br /> cannot run arbitrary command lines. After validation, the values <br /> supplied in the HTML are passed to the Windows CreateProcessA API.<br /> <br /> <br /> The validation can be bypassed allowing for running arbitrary command<br /> lines. The command line can specify running remote files (example: UNC <br /> command line).<br /> <br /> <br /> A function exists at offset 100019B0 of bwocxrun.ocx. Inside this <br /> function, there are 3 calls to strstr to check the contents of the user <br /> specified command line. If “\setup.exe,” “\bwvbprt.exe,” or <br /> “\bwvbprtl.exe” are contained in the command line (strstr returns <br /> nonzero value), the command line passes validation and is then passed to<br /> CreateProcessA.
Severity CVSS v4.0: Pending analysis
Last modification:
19/09/2025

CVE-2014-2139

Publication date:
12/04/2014
Cisco ONS 15454 controller cards with software 9.6 and earlier allow remote attackers to cause a denial of service (flash write outage) via a TCP FIN attack that triggers file-descriptor exhaustion, aka Bug ID CSCug97315.
Severity CVSS v4.0: Pending analysis
Last modification:
12/04/2025

CVE-2014-2140

Publication date:
12/04/2014
Cisco ONS 15454 controller cards with software 9.6 and earlier allow remote attackers to cause a denial of service (card reset) via a TCP FIN attack that triggers file-descriptor exhaustion and a failure to open a CAL pipe, aka Bug ID CSCug97348.
Severity CVSS v4.0: Pending analysis
Last modification:
12/04/2025