Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-24939

Publication date:
16/06/2021
Prototype pollution in Stampit supermixer 1.0.3 allows an attacker to modify the prototype of a base object which can vary in severity depending on the implementation.
Severity CVSS v4.0: Pending analysis
Last modification:
02/12/2022

CVE-2020-20444

Publication date:
16/06/2021
Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET parameter in '/shared/view_source.php' which "could" lead to RCE vulnerability .
Severity CVSS v4.0: Pending analysis
Last modification:
29/09/2022

CVE-2020-22198

Publication date:
16/06/2021
SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.
Severity CVSS v4.0: Pending analysis
Last modification:
21/06/2021

CVE-2020-35761

Publication date:
16/06/2021
bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code.
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2021

CVE-2020-35760

Publication date:
16/06/2021
bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files).
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2021

CVE-2020-35759

Publication date:
16/06/2021
bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).
Severity CVSS v4.0: Pending analysis
Last modification:
17/06/2021

CVE-2020-27339

Publication date:
16/06/2021
In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize parameters, allowing callers to corrupt either the firmware or the OS memory. The fixed versions for this issue in the AhciBusDxe, IdeBusDxe, NvmExpressDxe, SdHostDriverDxe, and SdMmcDeviceDxe drivers are 05.16.25, 05.26.25, 05.35.25, 05.43.25, and 05.51.25 (for Kernel 5.1 through 5.5).
Severity CVSS v4.0: Pending analysis
Last modification:
04/11/2025

CVE-2021-34803

Publication date:
16/06/2021
TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations.
Severity CVSS v4.0: Pending analysis
Last modification:
06/04/2022

CVE-2021-34801

Publication date:
16/06/2021
Valine 1.4.14 allows remote attackers to cause a denial of service (application outage) by supplying a ua (aka User-Agent) value that only specifies the product and version.
Severity CVSS v4.0: Pending analysis
Last modification:
03/05/2022

CVE-2021-27610

Publication date:
16/06/2021
SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about internal and external RFC user in consistent and distinguished format, which could lead to improper authentication and may be exploited by malicious users to obtain illegitimate access to the system.
Severity CVSS v4.0: Pending analysis
Last modification:
06/10/2022

CVE-2020-8300

Publication date:
16/06/2021
Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a SAML SP or a SAML IdP for this to be possible.
Severity CVSS v4.0: Pending analysis
Last modification:
20/09/2022

CVE-2021-21667

Publication date:
16/06/2021
Jenkins Scriptler Plugin 3.2 and earlier does not escape parameter names shown in job configuration forms, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Scriptler/Configure permission.
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2023