Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-15817

Publication date:
08/08/2020
In JetBrains YouTrack before 2020.1.1331, an external user could execute commands against arbitrary issues.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-15818

Publication date:
08/08/2020
In JetBrains YouTrack before 2020.2.8527, the subtasks workflow could disclose issue existence.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2019-19704

Publication date:
08/08/2020
In JetBrains Upsource before 2020.1, information disclosure is possible because of an incorrect user matching algorithm.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-15819

Publication date:
08/08/2020
JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports.
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2020

CVE-2020-15058

Publication date:
07/08/2020
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-15061

Publication date:
07/08/2020
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to denial-of-service the device via long input values.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-15062

Publication date:
07/08/2020
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-15065

Publication date:
07/08/2020
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to denial-of-service the device via long input values.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-15063

Publication date:
07/08/2020
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
09/08/2020

CVE-2020-15064

Publication date:
07/08/2020
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name.
Severity CVSS v4.0: Pending analysis
Last modification:
09/08/2020

CVE-2020-15059

Publication date:
07/08/2020
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
09/08/2020

CVE-2020-15060

Publication date:
07/08/2020
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name.
Severity CVSS v4.0: Pending analysis
Last modification:
09/08/2020