Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-16141

Publication date:
09/09/2019
An issue was discovered in the once_cell crate before 1.0.1 for Rust. There is a panic during initialization of Lazy.
Severity CVSS v4.0: Pending analysis
Last modification:
09/09/2019

CVE-2019-16140

Publication date:
09/09/2019
An issue was discovered in the chttp crate before 0.1.3 for Rust. There is a use-after-free during buffer conversion.
Severity CVSS v4.0: Pending analysis
Last modification:
22/11/2023

CVE-2019-16139

Publication date:
09/09/2019
An issue was discovered in the compact_arena crate before 0.4.0 for Rust. Generativity is mishandled, leading to an out-of-bounds write or read.
Severity CVSS v4.0: Pending analysis
Last modification:
09/09/2019

CVE-2019-16138

Publication date:
09/09/2019
An issue was discovered in the image crate before 0.21.3 for Rust, affecting the HDR image format decoder. Vec::set_len is called on an uninitialized vector, leading to a use-after-free and arbitrary code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
10/09/2019

CVE-2019-16137

Publication date:
09/09/2019
An issue was discovered in the spin crate before 0.5.2 for Rust, when RwLock is used. Because memory ordering is mishandled, two writers can acquire the lock at the same time, violating mutual exclusion.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-16130

Publication date:
09/09/2019
YII2-CMS v1.0 has XSS in protected\core\modules\home\models\Contact.php via a name field to /contact.html.
Severity CVSS v4.0: Pending analysis
Last modification:
09/09/2019

CVE-2019-16133

Publication date:
09/09/2019
An issue was discovered in eteams OA v4.0.34. Because the session is not strictly checked, the account names and passwords of all employees in the company can be obtained by an ordinary account. Specifically, the attacker sends a jsessionid value for URIs under app/profile/summary/.
Severity CVSS v4.0: Pending analysis
Last modification:
10/09/2019

CVE-2019-16132

Publication date:
09/09/2019
An issue was discovered in OKLite v1.2.25. framework/admin/tpl_control.php allows remote attackers to delete arbitrary files via a title directory-traversal pathname followed by a crafted substring.
Severity CVSS v4.0: Pending analysis
Last modification:
10/09/2019

CVE-2019-16131

Publication date:
09/09/2019
framework/admin/modulec_control.php in OKLite v1.2.25 has an Arbitrary File Upload Vulnerability because a .php file from a ZIP archive can be written to /data/cache/.
Severity CVSS v4.0: Pending analysis
Last modification:
10/09/2019

CVE-2019-16123

Publication date:
09/09/2019
In Kartatopia PilusCart 1.4.1, the parameter filename in the file catalog.php is mishandled, leading to ../ Local File Disclosure.
Severity CVSS v4.0: Pending analysis
Last modification:
14/02/2024

CVE-2019-16126

Publication date:
09/09/2019
Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.
Severity CVSS v4.0: Pending analysis
Last modification:
09/09/2019

CVE-2019-16125

Publication date:
09/09/2019
In Jobberbase 2.0, the parameter category is not sanitized in public/page_subscribe.php, leading to /subscribe SQL injection.
Severity CVSS v4.0: Pending analysis
Last modification:
14/02/2024