Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-1673

Publication date:
12/10/2018
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145108.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2018-17929

Publication date:
11/10/2018
In Delta Industrial Automation TPEditor, TPEditor Versions 1.90 and prior, multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files lacking user input validation before copying data from project files onto the stack and may allow an attacker to remotely execute arbitrary code.
Severity CVSS v4.0: Pending analysis
Last modification:
18/09/2020

CVE-2018-17927

Publication date:
11/10/2018
In Delta Industrial Automation TPEditor, TPEditor Versions 1.90 and prior, multiple out-of-bounds write vulnerabilities may be exploited by processing specially crafted project files lacking user input validation, which may cause the system to write outside the intended buffer area and may allow remote code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2018-12441

Publication date:
11/10/2018
The CorsairService Service in Corsair Utility Engine is installed with insecure default permissions, which allows unprivileged local users to execute arbitrary commands via modification of the CorsairService BINARY_PATH_NAME, leading to complete control of the affected system. The issue exists due to the Windows "Everyone" group being granted SERVICE_ALL_ACCESS permissions to the CorsairService Service.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2018-18257

Publication date:
11/10/2018
An issue was discovered in BageCMS 3.1.3. An attacker can delete any files and folders on the web server via an index.php?r=admini/template/batch&command=deleteFile&fileName= or index.php?r=admini/template/batch&command=deleteFolder&folderName=../ directory traversal URI.
Severity CVSS v4.0: Pending analysis
Last modification:
29/11/2018

CVE-2018-18258

Publication date:
11/10/2018
An issue was discovered in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any file on the web server via an index.php?r=admini/template/updateTpl&filename= URI.
Severity CVSS v4.0: Pending analysis
Last modification:
26/06/2019

CVE-2018-15766

Publication date:
11/10/2018
On install, Dell Encryption versions prior 10.0.1 and Dell Endpoint Security Suite Enterprise versions prior 2.0.1 will overwrite and manually set the "Minimum Password Length" group policy object to a value of 1 on that device. This allows for users to bypass any existing policy for password length and potentially create insecure password on their device. This value is defined during the installation of the "Encryption Management Agent" or "EMAgent" application. There are no other known values modified.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2018-18215

Publication date:
11/10/2018
In youke365 v1.1.5, admin/user.html has a CSRF vulnerability that can add an user account.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2018

CVE-2018-9206

Publication date:
11/10/2018
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload
Severity CVSS v4.0: Pending analysis
Last modification:
11/09/2019

CVE-2018-18242

Publication date:
11/10/2018
youke365 v1.1.5 has SQL injection via admin/login.html, as demonstrated by username=admin&pass=123456&code=9823&act=login&submit=%E7%99%BB+%E9%99%86.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2018

CVE-2018-12449

Publication date:
11/10/2018
The Whale browser installer 0.4.3.0 and earlier versions allows DLL hijacking.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2018-1738

Publication date:
11/10/2018
IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0 could allow an authenticated user to obtain highly sensitive information or jeopardize system integrity due to improper authentication mechanisms. IBM X-Force ID: 147907.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019