Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-17452

Publication date:
09/08/2020
flatCore before 1.5.7 allows upload and execution of a .php file by an admin.
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2020

CVE-2020-17451

Publication date:
09/08/2020
flatCore before 1.5.7 allows XSS by an admin via the acp/acp.php?tn=pages&sub=edit&editpage=1 page_linkname, page_title, page_content, or page_extracontent parameter, or the acp/acp.php?tn=system&sub=sys_pref prefs_pagename, prefs_pagetitle, or prefs_pagesubtitle parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2020

CVE-2020-17447

Publication date:
09/08/2020
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-15139. Reason: This candidate is a duplicate of CVE-2020-15139. Notes: All CVE users should reference CVE-2020-15139 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-16248

Publication date:
09/08/2020
Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
04/08/2024

CVE-2020-15820

Publication date:
08/08/2020
In JetBrains YouTrack before 2020.2.6881, the markdown parser could disclose hidden file existence.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-15824

Publication date:
08/08/2020
In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by default.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-15825

Publication date:
08/08/2020
In JetBrains TeamCity before 2020.1, users with the Modify Group permission can elevate other users' privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-15826

Publication date:
08/08/2020
In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-15828

Publication date:
08/08/2020
In JetBrains TeamCity before 2020.1.1, project parameter values can be retrieved by a user without appropriate permissions.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-15829

Publication date:
08/08/2020
In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-15831

Publication date:
08/08/2020
JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI.
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2020

CVE-2020-15830

Publication date:
08/08/2020
JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI.
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2020