Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-21026

Publication date:
12/11/2019
A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.6.5-00 allows an unauthenticated remote user to read internal information.
Severity CVSS v4.0: Pending analysis
Last modification:
18/11/2019

CVE-2019-17234

Publication date:
12/11/2019
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary file deletion.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2019-17235

Publication date:
12/11/2019
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2012-1572

Publication date:
12/11/2019
OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2019-17236

Publication date:
12/11/2019
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress is vulnerable to stored XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
12/11/2019

CVE-2019-17237

Publication date:
12/11/2019
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF.
Severity CVSS v4.0: Pending analysis
Last modification:
12/11/2019

CVE-2019-18924

Publication date:
12/11/2019
Systematic IRIS WebForms 5.4 is vulnerable to directory traversal. By manipulating variables that reference files with ../ (and variations), it is possible to list all the directories and check if a particular file exists.
Severity CVSS v4.0: Pending analysis
Last modification:
13/11/2019

CVE-2019-18925

Publication date:
12/11/2019
Systematic IRIS WebForms 5.4 and its functionalities can be accessed and used without any form of authentication.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-18926

Publication date:
12/11/2019
Systematic IRIS Standards Management (ISM) v2.1 SP1 89 is vulnerable to unauthenticated reflected Cross Site Scripting (XSS). A user input (related to dialog information) is reflected directly in the web page, allowing a malicious user to conduct a Cross Site Scripting attack against users of the application.
Severity CVSS v4.0: Pending analysis
Last modification:
14/11/2019

CVE-2019-18655

Publication date:
12/11/2019
File Sharing Wizard version 1.5.0 build 2008 is affected by a Structured Exception Handler based buffer overflow vulnerability. An unauthenticated attacker is able to perform remote command execution and obtain a command shell by sending a HTTP GET request including the malicious payload in the URL. A similar issue to CVE-2019-17415, CVE-2019-16724, and CVE-2010-2331.
Severity CVSS v4.0: Pending analysis
Last modification:
08/10/2024

CVE-2019-4652

Publication date:
12/11/2019
IBM Spectrum Protect Plus 10.1.0 through 10.1.4 uses insecure file permissions on restored files and directories in Windows which could allow a local user to obtain sensitive information or perform unauthorized actions. IBM X-Force ID: 170963.
Severity CVSS v4.0: Pending analysis
Last modification:
14/11/2019

CVE-2019-18848

Publication date:
12/11/2019
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string.
Severity CVSS v4.0: Pending analysis
Last modification:
03/05/2022