Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-27217

Publication date:
04/03/2021
An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not correctly validate the embedded length field of an authenticated message received from the device. Out-of-bounds reads performed by aes_remove_padding() can crash the running process, depending on the memory layout. This could be used by an attacker to cause a client-side denial of service. The yubihsm-shell project is included in the YubiHSM 2 SDK product.
Severity CVSS v4.0: Pending analysis
Last modification:
26/03/2021

CVE-2021-26028

Publication date:
04/03/2021
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path.
Severity CVSS v4.0: Pending analysis
Last modification:
10/03/2021

CVE-2021-23130

Publication date:
04/03/2021
An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of feed fields could lead to xss issues.
Severity CVSS v4.0: Pending analysis
Last modification:
05/03/2021

CVE-2021-23132

Publication date:
04/03/2021
An issue was discovered in Joomla! 3.0.0 through 3.9.24. com_media allowed paths that are not intended for image uploads
Severity CVSS v4.0: Pending analysis
Last modification:
05/03/2021

CVE-2021-23131

Publication date:
04/03/2021
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Missing input validation within the template manager.
Severity CVSS v4.0: Pending analysis
Last modification:
05/03/2021

CVE-2021-23129

Publication date:
04/03/2021
An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of messages showed to users that could lead to xss issues.
Severity CVSS v4.0: Pending analysis
Last modification:
05/03/2021

CVE-2021-23128

Publication date:
04/03/2021
An issue was discovered in Joomla! 3.2.0 through 3.9.24. The core shipped but unused randval implementation within FOF (FOFEncryptRandval) used an potential insecure implemetation. That has now been replaced with a call to 'random_bytes()' and its backport that is shipped within random_compat.
Severity CVSS v4.0: Pending analysis
Last modification:
05/03/2021

CVE-2021-23127

Publication date:
04/03/2021
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of an insufficient length for the 2FA secret accoring to RFC 4226 of 10 bytes vs 20 bytes.
Severity CVSS v4.0: Pending analysis
Last modification:
05/03/2021

CVE-2021-22128

Publication date:
04/03/2021
An improper access control vulnerability in FortiProxy SSL VPN portal 2.0.0, 1.2.9 and below versions may allow an authenticated, remote attacker to access internal service such as the ZebOS Shell on the FortiProxy appliance through the Quick Connection functionality.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2022

CVE-2021-26027

Publication date:
04/03/2021
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthorized change of the category for an article.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2022

CVE-2021-26029

Publication date:
04/03/2021
An issue was discovered in Joomla! 1.6.0 through 3.9.24. Inadequate filtering of form contents could allow to overwrite the author field.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2022

CVE-2021-23126

Publication date:
04/03/2021
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function within the process of generating the 2FA secret.
Severity CVSS v4.0: Pending analysis
Last modification:
08/08/2023