Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-7525

Publication date:
31/08/2020
Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and Wiser for KNX (formerly homeLYnk) which could allow an attacker to guess a password when brute force is used.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2020

CVE-2020-7522

Publication date:
31/08/2020
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method of `SoundUploadServlet` which may lead to uploading executable files to non-specified directories.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2020

CVE-2020-7521

Publication date:
31/08/2020
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method of `FileUploadServlet` which may lead to uploading executable files to non-specified directories.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2020

CVE-2020-20628

Publication date:
31/08/2020
controller/controller-comments.php in WP GDPR plugin through 2.1.1 has unauthenticated stored XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
31/08/2020

CVE-2020-20627

Publication date:
31/08/2020
The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change.
Severity CVSS v4.0: Pending analysis
Last modification:
06/02/2023

CVE-2020-20626

Publication date:
31/08/2020
lara-google-analytics.php in Lara Google Analytics plugin through 2.0.4 for WordPress allows authenticated stored XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2020

CVE-2020-24699

Publication date:
31/08/2020
The Chamber Dashboard Business Directory plugin 3.2.8 for WordPress allows XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2020

CVE-2020-20625

Publication date:
31/08/2020
Sliced Invoices plugin for WordPress 3.8.2 and earlier allows unauthenticated information disclosure and authenticated SQL injection via core/class-sliced.php.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2020

CVE-2020-24363

Publication date:
31/08/2020
TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2025

CVE-2020-13463

Publication date:
31/08/2020
The flash memory readout protection in Apex Microelectronics APM32F103 devices allows physical attackers to extract firmware via the debug interface and exception handling.
Severity CVSS v4.0: Pending analysis
Last modification:
10/09/2020

CVE-2020-13464

Publication date:
31/08/2020
The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attackers to extract firmware via the debug interface by utilizing the CPU or DMA module.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-13828

Publication date:
31/08/2020
Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated attackers to inject arbitrary web script or HTML via ticket/card.php?action=create with the subject, message, or address parameter; adherents/card.php with the societe or address parameter; product/card.php with the label or customcode parameter; or societe/card.php with the alias or barcode parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
17/11/2022