Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-6293

Publication date:
12/08/2020
SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to access, modify or make unavailable existing files but the impact is limited to the files themselves and is restricted by other policies such as access control lists and other upload file size restrictions, leading to Unrestricted File Upload.
Severity CVSS v4.0: Pending analysis
Last modification:
13/08/2020

CVE-2020-6284

Publication date:
12/08/2020
SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user's privileges. If the accessing user has administrative privileges, then the execution of the script content could result in complete compromise of system confidentiality, integrity and availability, leading to Stored Cross Site Scripting.
Severity CVSS v4.0: Pending analysis
Last modification:
14/08/2020

CVE-2020-2229

Publication date:
12/08/2020
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
02/11/2023

CVE-2020-2230

Publication date:
12/08/2020
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.
Severity CVSS v4.0: Pending analysis
Last modification:
02/11/2023

CVE-2020-2231

Publication date:
12/08/2020
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.
Severity CVSS v4.0: Pending analysis
Last modification:
02/11/2023

CVE-2020-17496

Publication date:
12/08/2020
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2025

CVE-2020-13278

Publication date:
12/08/2020
Reflected Cross-Site Scripting vulnerability in Modules.php in RosarioSIS Student Information System
Severity CVSS v4.0: Pending analysis
Last modification:
17/08/2020

CVE-2020-16145

Publication date:
12/08/2020
Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-17372

Publication date:
12/08/2020
SugarCRM before 10.1.0 (Q3 2020) allows XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
13/08/2020

CVE-2020-16266

Publication date:
12/08/2020
An XSS issue was discovered in MantisBT before 2.24.2. Improper escaping on view_all_bug_page.php allows a remote attacker to inject arbitrary HTML into the page by saving it into a text Custom Field, leading to possible code execution in the browser of any user subsequently viewing the issue (if CSP settings allow it).
Severity CVSS v4.0: Pending analysis
Last modification:
17/08/2020

CVE-2020-6932

Publication date:
12/08/2020
An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versions 6.4.0 to 6.6.0 could allow an attacker to potentially read arbitrary files and run arbitrary executables in the context of the web server.
Severity CVSS v4.0: Pending analysis
Last modification:
22/08/2025

CVE-2020-17373

Publication date:
12/08/2020
SugarCRM before 10.1.0 (Q3 2020) allows SQL Injection.
Severity CVSS v4.0: Pending analysis
Last modification:
16/11/2022