Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-28127

Publication date:
01/07/2021
An issue was discovered in Stormshield SNS through 4.2.1. A brute-force attack can occur.
Severity CVSS v4.0: Pending analysis
Last modification:
07/07/2021

CVE-2021-35337

Publication date:
01/07/2021
Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any attacker will be able to see the invoices of different users by changing the id parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
03/05/2022

CVE-2021-27661

Publication date:
01/07/2021
Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Controller (F4-SNC) user an unintended level of access to the controller’s file system, allowing them to access or modify system files by sending specifically crafted web messages to the F4-SNC.
Severity CVSS v4.0: Pending analysis
Last modification:
07/07/2021

CVE-2021-27660

Publication date:
01/07/2021
An insecure client auto update feature in C-CURE 9000 can allow remote execution of lower privileged Windows programs.
Severity CVSS v4.0: Pending analysis
Last modification:
06/07/2021

CVE-2021-35336

Publication date:
01/07/2021
Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control. A vulnerability in the Tieline Web Administrative Interface could allow an unauthenticated user to access a sensitive part of the system with a high privileged account.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2022

CVE-2021-27477

Publication date:
01/07/2021
When JTEKT Corporation TOYOPUC PLC versions PC10G-CPU, 2PORT-EFR, Plus CPU, Plus EX, Plus EX2, Plus EFR, Plus EFR2, Plus 2P-EFR, PC10P-DP, PC10P-DP-IO, Plus BUS-EX, Nano 10GX, Nano 2ET,PC10PE, PC10PE-16/16P, PC10E, FL/ET-T-V2H, PC10B,PC10B-P, Nano CPU, PC10P, and PC10GE receive an invalid frame, the outside area of a receive buffer for FL-net are overwritten. As a result, the PLC CPU detects a system error, and the affected products stop.
Severity CVSS v4.0: Pending analysis
Last modification:
07/10/2022

CVE-2021-22344

Publication date:
01/07/2021
There is an Improper Access Control vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause temporary DoS.
Severity CVSS v4.0: Pending analysis
Last modification:
28/06/2022

CVE-2021-31813

Publication date:
01/07/2021
Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.
Severity CVSS v4.0: Pending analysis
Last modification:
21/09/2021

CVE-2021-22343

Publication date:
01/07/2021
There is a Configuration Defect vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service integrity and availability.
Severity CVSS v4.0: Pending analysis
Last modification:
06/07/2021

CVE-2020-9158

Publication date:
01/07/2021
There is a Missing Cryptographic Step vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause DoS of Samgr.
Severity CVSS v4.0: Pending analysis
Last modification:
06/07/2021

CVE-2021-22347

Publication date:
01/07/2021
There is an Improper Access Control vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause temporary DoS.
Severity CVSS v4.0: Pending analysis
Last modification:
28/06/2022

CVE-2021-20778

Publication date:
01/07/2021
Improper access control vulnerability in EC-CUBE 4.0.6 (EC-CUBE 4 series) allows a remote attacker to bypass access restriction and obtain sensitive information via unspecified vectors.
Severity CVSS v4.0: Pending analysis
Last modification:
28/06/2022