Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-14106

Publication date:
08/04/2021
The application in the mobile phone can unauthorized access to the list of running processes in the mobile phone, Xiaomi Mobile Phone MIUI
Severity CVSS v4.0: Pending analysis
Last modification:
14/04/2021

CVE-2020-14103

Publication date:
08/04/2021
The application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI
Severity CVSS v4.0: Pending analysis
Last modification:
14/04/2021

CVE-2021-29154

Publication date:
08/04/2021
BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute arbitrary code within the kernel context. This affects arch/x86/net/bpf_jit_comp.c and arch/x86/net/bpf_jit_comp32.c.
Severity CVSS v4.0: Pending analysis
Last modification:
25/03/2024

CVE-2021-3146

Publication date:
08/04/2021
The Dolby Audio X2 (DAX2) API service before 0.8.8.90 on Windows allows local users to gain privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
14/04/2021

CVE-2021-22312

Publication date:
08/04/2021
There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may exploit this vulnerability by sending specific message to the affected product. Due to not release the allocated memory properly, successful exploit may cause some service abnormal. Affected product include some versions of IPS Module, NGFW Module, Secospace USG6300, Secospace USG6500, Secospace USG6600 and USG9500.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2021

CVE-2021-3328

Publication date:
08/04/2021
An issue was discovered in Aprelium Abyss Web Server X1 2.12.1 and 2.14. A crafted HTTP request can lead to an out-of-bounds read that crashes the application.
Severity CVSS v4.0: Pending analysis
Last modification:
14/04/2021

CVE-2020-14099

Publication date:
08/04/2021
On Xiaomi router AX1800 rom version
Severity CVSS v4.0: Pending analysis
Last modification:
14/04/2021

CVE-2021-22115

Publication date:
08/04/2021
Cloud Controller API versions prior to 1.106.0 logs service broker credentials if the default value of db logging config field is changed. CAPI database logs service broker password in plain text whenever a job to clean up orphaned items is run by Cloud Controller.
Severity CVSS v4.0: Pending analysis
Last modification:
14/04/2021

CVE-2021-22507

Publication date:
08/04/2021
Authentication bypass vulnerability in Micro Focus Operations Bridge Manager affects versions 2019.05, 2019.11, 2020.05 and 2020.10. The vulnerability could allow remote attackers to bypass user authentication and get unauthorized access.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-14104

Publication date:
08/04/2021
A RACE CONDITION on XQBACKUP causes a decompression path error on Xiaomi router AX3600 with ROM version =1.0.50.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2021

CVE-2020-23539

Publication date:
08/04/2021
An issue was discovered in Realtek rtl8723de BLE Stack
Severity CVSS v4.0: Pending analysis
Last modification:
14/04/2021

CVE-2021-27945

Publication date:
08/04/2021
The Squirro Insights Engine was affected by a Reflected Cross-Site Scripting (XSS) vulnerability affecting versions 2.0.0 up to and including 3.2.4. An attacker can use the vulnerability to inject malicious JavaScript code into the application, which will execute within the browser of any user who views the relevant application content. The attacker-supplied code can perform a wide variety of actions, such as stealing victims' session tokens or login credentials, performing arbitrary actions on their behalf, and logging their keystrokes.
Severity CVSS v4.0: Pending analysis
Last modification:
14/04/2021