Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-7020

Publication date:
22/10/2020
Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex queries. This could result in the search disclosing the existence of documents the attacker should not be able to view. This could result in an attacker gaining additional insight into potentially sensitive indices.
Severity CVSS v4.0: Pending analysis
Last modification:
03/06/2022

CVE-2020-27533

Publication date:
22/10/2020
A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.
Severity CVSS v4.0: Pending analysis
Last modification:
03/06/2022

CVE-2020-26649

Publication date:
22/10/2020
AtomXCMS 2.0 is affected by Incorrect Access Control via admin/dump.php
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-26650

Publication date:
22/10/2020
AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-24033

Publication date:
22/10/2020
An issue was discovered in fs.com S3900 24T4S 1.7.0 and earlier. The form does not have an authentication or token authentication mechanism that allows remote attackers to forge requests on behalf of a site administrator to change all settings including deleting users, creating new users with escalated privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
02/11/2020

CVE-2020-27646

Publication date:
22/10/2020
Biscom Secure File Transfer (SFT) before 5.1.1082 and 6.x before 6.0.1011 allows user credential theft.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-27560

Publication date:
22/10/2020
ImageMagick 7.0.10-34 allows Division by Zero in OptimizeLayerFrames in MagickCore/layer.c, which may cause a denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
11/03/2023

CVE-2020-27642

Publication date:
22/10/2020
A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.
Severity CVSS v4.0: Pending analysis
Last modification:
27/10/2020

CVE-2020-27638

Publication date:
22/10/2020
receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-27621

Publication date:
22/10/2020
The FileImporter extension in MediaWiki through 1.35.0 was not properly attributing various user actions to a specific user's IP address. Instead, for various actions, it would report the IP address of an internal Wikimedia Foundation server by omitting X-Forwarded-For data. This resulted in an inability to properly audit and attribute various user actions performed via the FileImporter extension.
Severity CVSS v4.0: Pending analysis
Last modification:
02/11/2020

CVE-2020-27620

Publication date:
22/10/2020
The Cosmos Skin for MediaWiki through 1.35.0 has stored XSS because MediaWiki messages were not being properly escaped. This is related to wfMessage and Html::rawElement, as demonstrated by CosmosSocialProfile::getUserGroups.
Severity CVSS v4.0: Pending analysis
Last modification:
26/10/2020

CVE-2020-27619

Publication date:
22/10/2020
In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.
Severity CVSS v4.0: Pending analysis
Last modification:
03/02/2024