Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2017-18366

Publication date:
15/04/2019
Subrion CMS 4.1.5 has CSRF in blog/delete/.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2019

CVE-2017-7775

Publication date:
15/04/2019
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2018-16257

Publication date:
12/04/2019
There are multiple XSS vulnerabilities in WP All Import plugin 3.4.9 for WordPress via action=template. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2024

CVE-2018-16258

Publication date:
12/04/2019
There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-import custom_type. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2024

CVE-2018-16259

Publication date:
12/04/2019
There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-settings large_feed_limit. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2024

CVE-2019-10880

Publication date:
12/04/2019
Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2017-7772

Publication date:
12/04/2019
Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2019

CVE-2018-13137

Publication date:
12/04/2019
The Events Manager plugin 5.9.4 for WordPress has XSS via the dbem_event_reapproved_email_body parameter to the wp-admin/edit.php?post_type=event&page=events-manager-options URI.
Severity CVSS v4.0: Pending analysis
Last modification:
08/10/2024

CVE-2018-16254

Publication date:
12/04/2019
There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=options. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2024

CVE-2018-16255

Publication date:
12/04/2019
There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=evaluate. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2024

CVE-2018-16256

Publication date:
12/04/2019
There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via Add Filtering Options(Add Rule). NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2024

CVE-2019-1574

Publication date:
12/04/2019
Cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition Migration tool 1.1.12 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the Devices View.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2019