Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-13029

Publication date:
11/07/2019
Multiple stored Cross-site scripting (XSS) issues in the admin panel and survey system in REDCap 8 before 8.10.20 and 9 before 9.1.2 allow an attacker to inject arbitrary malicious HTML or JavaScript code into a user's web browser.
Severity CVSS v4.0: Pending analysis
Last modification:
19/03/2025

CVE-2018-17150

Publication date:
11/07/2019
Intersystems Cache 2017.2.2.865.0 allows XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2019

CVE-2018-17151

Publication date:
11/07/2019
Intersystems Cache 2017.2.2.865.0 has Incorrect Access Control.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2019

CVE-2018-17152

Publication date:
11/07/2019
Intersystems Cache 2017.2.2.865.0 allows XXE.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2019

CVE-2018-19588

Publication date:
11/07/2019
Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control.
Severity CVSS v4.0: Pending analysis
Last modification:
18/07/2019

CVE-2019-10135

Publication date:
11/07/2019
A flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1. Insecure use of the yaml.load() function allowed the user to load any suspicious object for code execution via the parsing of malicious YAML files.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2022

CVE-2019-10192

Publication date:
11/07/2019
A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog using the SETRANGE command, an attacker could trick Redis interpretation of dense HLL encoding to write up to 3 bytes beyond the end of a heap-allocated buffer.
Severity CVSS v4.0: Pending analysis
Last modification:
28/10/2021

CVE-2019-10193

Publication date:
11/07/2019
A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRANGE command, an attacker could cause Redis to perform controlled increments of up to 12 bytes past the end of a stack-allocated buffer.
Severity CVSS v4.0: Pending analysis
Last modification:
28/10/2021

CVE-2019-11062

Publication date:
11/07/2019
The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". The target server can be exploited without authentication.
Severity CVSS v4.0: Pending analysis
Last modification:
01/03/2023

CVE-2019-10194

Publication date:
11/07/2019
Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could be disclosed in log files (if playbooks are run with -v) or in playbooks stored on Metrics or Bastion hosts.
Severity CVSS v4.0: Pending analysis
Last modification:
01/03/2023

CVE-2019-10651

Publication date:
11/07/2019
An issue was discovered in the Core Server in Ivanti Endpoint Manager (EPM) 2017.3 before SU7 and 2018.x before 2018.3 SU3, with remote code execution. In other words, the issue affects 2017.3, 2018.1, and 2018.3 installations that lack the April 2019 update.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-11268

Publication date:
11/07/2019
Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can extend those reading privileges to all other identity zones and obtain private information on users, clients, and groups in all other identity zones.
Severity CVSS v4.0: Pending analysis
Last modification:
02/10/2020