Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-38302

Publication date:
13/08/2021
The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection.
Severity CVSS v4.0: Pending analysis
Last modification:
23/08/2021

CVE-2021-36786

Publication date:
13/08/2021
The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows Sensitive Data Exposure of API credentials and private keys.
Severity CVSS v4.0: Pending analysis
Last modification:
23/08/2021

CVE-2021-38623

Publication date:
13/08/2021
The deferred_image_processing (aka Deferred image processing) extension before 1.0.2 for TYPO3 allows Denial of Service via the FAL API because of /var/transient disk consumption.
Severity CVSS v4.0: Pending analysis
Last modification:
23/08/2021

CVE-2021-36785

Publication date:
13/08/2021
The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
20/08/2021

CVE-2021-36790

Publication date:
13/08/2021
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
20/08/2021

CVE-2021-36789

Publication date:
13/08/2021
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection.
Severity CVSS v4.0: Pending analysis
Last modification:
20/08/2021

CVE-2021-36788

Publication date:
13/08/2021
The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
20/08/2021

CVE-2021-34823

Publication date:
13/08/2021
The ON24 ScreenShare (aka DesktopScreenShare.app) plugin before 2.0 for macOS allows remote file access via its built-in HTTP server. This allows unauthenticated remote users to retrieve files accessible to the logged-on macOS user. When a remote user sends a crafted HTTP request to the server, it triggers a code path that will download a configuration file from a specified remote machine over HTTP. There is an XXE flaw in processing of this configuration file that allows reading local (to macOS) files and uploading them to remote machines.
Severity CVSS v4.0: Pending analysis
Last modification:
31/08/2021

CVE-2020-18759

Publication date:
13/08/2021
An information disclosure vulnerability exists in the EPA protocol of Dut Computer Control Engineering Co.'s PLC MAC1100.
Severity CVSS v4.0: Pending analysis
Last modification:
25/08/2021

CVE-2020-18753

Publication date:
13/08/2021
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to gain access to the system and escalate privileges via a crafted packet.
Severity CVSS v4.0: Pending analysis
Last modification:
25/08/2021

CVE-2020-18758

Publication date:
13/08/2021
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to execute arbitrary code.
Severity CVSS v4.0: Pending analysis
Last modification:
25/08/2021

CVE-2020-18757

Publication date:
13/08/2021
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to cause persistent denial of service (DOS) via a crafted packet.
Severity CVSS v4.0: Pending analysis
Last modification:
25/08/2021