Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-4665

Publication date:
16/11/2020
IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 186280.
Severity CVSS v4.0: Pending analysis
Last modification:
23/11/2020

CVE-2020-4655

Publication date:
16/11/2020
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 186091.
Severity CVSS v4.0: Pending analysis
Last modification:
23/11/2020

CVE-2020-4647

Publication date:
16/11/2020
IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
Severity CVSS v4.0: Pending analysis
Last modification:
23/11/2020

CVE-2020-4692

Publication date:
16/11/2020
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 could allow an authenticated user to obtain sensitive information from the Dashboard UI. IBM X-Force ID: 186780.
Severity CVSS v4.0: Pending analysis
Last modification:
23/11/2020

CVE-2020-4672

Publication date:
16/11/2020
IBM Business Automation Workflow 20.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186285.
Severity CVSS v4.0: Pending analysis
Last modification:
23/11/2020

CVE-2020-28723

Publication date:
16/11/2020
Memory leak in IPv6Param::setAddress in CloudAvid PParam 1.3.1.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-27989

Publication date:
16/11/2020
Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard).
Severity CVSS v4.0: Pending analysis
Last modification:
17/11/2020

CVE-2020-27988

Publication date:
16/11/2020
Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).
Severity CVSS v4.0: Pending analysis
Last modification:
17/11/2020

CVE-2020-27623

Publication date:
16/11/2020
JetBrains IdeaVim before version 0.58 might have caused an information leak in limited circumstances.
Severity CVSS v4.0: Pending analysis
Last modification:
30/11/2020

CVE-2020-27627

Publication date:
16/11/2020
JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.
Severity CVSS v4.0: Pending analysis
Last modification:
01/12/2020

CVE-2020-27622

Publication date:
16/11/2020
In JetBrains IntelliJ IDEA before 2020.2, the built-in web server could expose information about the IDE version.
Severity CVSS v4.0: Pending analysis
Last modification:
23/11/2020

CVE-2020-27423

Publication date:
16/11/2020
Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox
Severity CVSS v4.0: Pending analysis
Last modification:
01/12/2020