Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2022-35408

Publication date:
22/09/2022
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM callout vulnerability in the SMM driver in UsbLegacyControlSmm leads to possible arbitrary code execution in SMM and escalation of privileges. An attacker could overwrite the function pointers in the EFI_BOOT_SERVICES table before the USB SMI handler triggers. (This is not exploitable from code running in the operating system.)
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2025

CVE-2022-40932

Publication date:
22/09/2022
In Zoo Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of the "gallery" file of the "Gallery" module in the background management system.
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2025

CVE-2022-38398

Publication date:
22/09/2022
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14.
Severity CVSS v4.0: Pending analysis
Last modification:
07/01/2024

CVE-2022-38648

Publication date:
22/09/2022
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14.
Severity CVSS v4.0: Pending analysis
Last modification:
07/01/2024

CVE-2022-40146

Publication date:
22/09/2022
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14.
Severity CVSS v4.0: Pending analysis
Last modification:
07/01/2024

CVE-2022-1941

Publication date:
22/09/2022
A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 4.21.5 for protobuf-python can lead to out of memory failures. A specially crafted message with multiple key-value per elements creates parsing issues, and can lead to a Denial of Service against services receiving unsanitized input. We recommend upgrading to versions 3.18.3, 3.19.5, 3.20.2, 3.21.6 for protobuf-cpp and 3.18.3, 3.19.5, 3.20.2, 4.21.6 for protobuf-python. Versions for 3.16 and 3.17 are no longer updated.
Severity CVSS v4.0: Pending analysis
Last modification:
01/08/2024

CVE-2022-40446

Publication date:
22/09/2022
ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&groupid=.
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2025

CVE-2022-40447

Publication date:
22/09/2022
ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the keyword parameter at /admin/baojia_list.php.
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2025

CVE-2022-40443

Publication date:
22/09/2022
An absolute path traversal vulnerability in ZZCMS 2022 allows attackers to obtain sensitive information via a crafted GET request sent to /one/siteinfo.php.
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2025

CVE-2022-40444

Publication date:
22/09/2022
ZZCMS 2022 was discovered to contain a full path disclosure vulnerability via the page /admin/index.PHP? _server.
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2025

CVE-2022-3256

Publication date:
22/09/2022
Use After Free in GitHub repository vim/vim prior to 9.0.0530.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2022-3267

Publication date:
22/09/2022
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.
Severity CVSS v4.0: Pending analysis
Last modification:
22/09/2022