Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-34639

Publication date:
05/08/2021
Authenticated File Upload in WordPress Download Manager
Severity CVSS v4.0: Pending analysis
Last modification:
21/03/2025

CVE-2021-34638

Publication date:
05/08/2021
Authenticated Directory Traversal in WordPress Download Manager
Severity CVSS v4.0: Pending analysis
Last modification:
21/03/2025

CVE-2021-34634

Publication date:
05/08/2021
The Nifty Newsletters WordPress plugin is vulnerable to Cross-Site Request Forgery via the sola_nl_wp_head function found in the ~/sola-newsletters.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.0.23.
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2021

CVE-2021-34633

Publication date:
05/08/2021
The Youtube Feeder WordPress plugin is vulnerable to Cross-Site Request Forgery via the printAdminPage function found in the ~/youtube-feeder.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.1.
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2021

CVE-2021-3566

Publication date:
05/08/2021
Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitimate "ffconcat" file that references an image, followed by a file the triggers the tty demuxer, the contents of the second file will be copied into the output file verbatim (as long as the `-vcodec copy` option is passed to ffmpeg).
Severity CVSS v4.0: Pending analysis
Last modification:
21/12/2022

CVE-2021-35325

Publication date:
05/08/2021
A stack overflow in the checkLoginUser function of TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to cause a denial of service (DOS).
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2021

CVE-2021-35326

Publication date:
05/08/2021
A vulnerability in TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows attackers to download the configuration file via sending a crafted HTTP request.
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2021

CVE-2021-35327

Publication date:
05/08/2021
A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default credentials via a crafted POST request.
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2021

CVE-2021-37156

Publication date:
05/08/2021
Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended behavior is for those sessions to be terminated.
Severity CVSS v4.0: Pending analysis
Last modification:
12/08/2021

CVE-2021-22928

Publication date:
05/08/2021
A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citrix Profile Management or Citrix Profile Management WMI Plugin installed to escalate their privilege level on that Windows VDA to SYSTEM.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2022

CVE-2021-32002

Publication date:
05/08/2021
Improper Access Control vulnerability in web service of Secomea SiteManager allows local attacker without credentials to gather network information and configuration of the SiteManager. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.
Severity CVSS v4.0: Pending analysis
Last modification:
02/07/2022

CVE-2021-22924

Publication date:
05/08/2021
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issuer cert' which a transfer can setto qualify how to verify the server certificate.
Severity CVSS v4.0: Pending analysis
Last modification:
09/06/2025