Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-11590

Publication date:
29/04/2019
The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-5492

Publication date:
29/04/2019
Element Plug-in for vCenter Server versions prior to 4.2.3 may disclose sensitive account information to an unauthenticated attacker. NetApp HCI Compute Node versions prior to 1.4P2 bundle affected versions of Element Plug-in for vCenter Server.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2016-10749

Publication date:
29/04/2019
parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a \ character.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2025

CVE-2019-11578

Publication date:
28/04/2019
auth.c in dhcpcd before 7.2.1 allowed attackers to infer secrets by performing latency attacks.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2019-11579

Publication date:
28/04/2019
dhcp.c in dhcpcd before 7.2.1 contains a 1-byte read overflow with DHO_OPTSOVERLOADED.
Severity CVSS v4.0: Pending analysis
Last modification:
22/04/2022

CVE-2019-11577

Publication date:
28/04/2019
dhcpcd before 7.2.1 contains a buffer overflow in dhcp6_findna in dhcp6.c when reading NA/TA addresses.
Severity CVSS v4.0: Pending analysis
Last modification:
29/04/2019

CVE-2019-11576

Publication date:
28/04/2019
Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, then an attacker could send them to the API without requiring the 2FA one-time password.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-11565

Publication date:
27/04/2019
Server Side Request Forgery (SSRF) exists in the Print My Blog plugin before 1.6.7 for WordPress via the site parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
01/05/2019

CVE-2019-11567

Publication date:
27/04/2019
An issue was discovered in AikCms v2.0. There is a SQL Injection vulnerability via $_GET['del'], as demonstrated by an admin/page/system/nav.php?del= URI.
Severity CVSS v4.0: Pending analysis
Last modification:
29/04/2019

CVE-2019-11568

Publication date:
27/04/2019
An issue was discovered in AikCms v2.0. There is a File upload vulnerability, as demonstrated by an admin/page/system/nav.php request with PHP code in a .php file with the application/octet-stream content type.
Severity CVSS v4.0: Pending analysis
Last modification:
29/04/2019

CVE-2019-11555

Publication date:
26/04/2019
The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate fragmentation reassembly state properly for a case where an unexpected fragment could be received. This could result in process termination due to a NULL pointer dereference (denial of service). This affects eap_server/eap_server_pwd.c and eap_peer/eap_pwd.c.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-11557

Publication date:
26/04/2019
The WebDorado Contact Form Builder plugin before 1.0.69 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.
Severity CVSS v4.0: Pending analysis
Last modification:
27/02/2023