Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2013-7324

Publication date:
17/02/2020
Webkit-GTK 2.x (any version with HTML5 audio/video support based on GStreamer) allows remote attackers to trigger unexpectedly high sound volume via malicious javascript. NOTE: this WebKit-GTK behavior complies with existing W3C standards and existing practices for GNOME desktop integration.
Severity CVSS v4.0: Pending analysis
Last modification:
28/02/2020

CVE-2015-6922

Publication date:
17/02/2020
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allows remote attackers to bypass authentication and (1) add an administrative account via crafted request to LocalAuth/setAccount.aspx or (2) write to and execute arbitrary files via a full pathname in the PathData parameter to ConfigTab/uploader.aspx.
Severity CVSS v4.0: Pending analysis
Last modification:
26/02/2020

CVE-2015-0258

Publication date:
17/02/2020
Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2) .php4, (3) .php5, or (4) .phtml extension.
Severity CVSS v4.0: Pending analysis
Last modification:
01/01/2022

CVE-2020-9043

Publication date:
17/02/2020
The wpCentral plugin before 1.5.1 for WordPress allows disclosure of the connection key.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-1704

Publication date:
17/02/2020
An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in the openshift/istio-kialia-rhel7-operator-container. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-12954

Publication date:
17/02/2020
SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users via a crafted onerror attribute of a VIDEO element in an action for an ALERT.
Severity CVSS v4.0: Pending analysis
Last modification:
28/02/2020

CVE-2013-3722

Publication date:
17/02/2020
A Denial of Service (infinite loop) exists in OpenSIPS before 1.10 in lookup.c.
Severity CVSS v4.0: Pending analysis
Last modification:
20/02/2020

CVE-2015-1387

Publication date:
17/02/2020
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-1454. Reason: This candidate is a reservation duplicate of CVE-2015-1454. Notes: All CVE users should reference CVE-2015-1454 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-6850

Publication date:
17/02/2020
Utilities.php in the miniorange-saml-20-single-sign-on plugin before 4.8.84 for WordPress allows XSS via a crafted SAML XML Response to wp-login.php. This is related to the SAMLResponse and RelayState variables, and the Destination parameter of the samlp:Response XML element.
Severity CVSS v4.0: Pending analysis
Last modification:
20/02/2020

CVE-2020-1692

Publication date:
17/02/2020
Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2020-9038

Publication date:
17/02/2020
Joplin through 1.0.184 allows Arbitrary File Read via XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
30/12/2021

CVE-2013-3738

Publication date:
17/02/2020
A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote malicious user execute arbitrary code.
Severity CVSS v4.0: Pending analysis
Last modification:
20/02/2020