Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-11579

Publication date:
28/04/2019
dhcp.c in dhcpcd before 7.2.1 contains a 1-byte read overflow with DHO_OPTSOVERLOADED.
Severity CVSS v4.0: Pending analysis
Last modification:
22/04/2022

CVE-2019-11577

Publication date:
28/04/2019
dhcpcd before 7.2.1 contains a buffer overflow in dhcp6_findna in dhcp6.c when reading NA/TA addresses.
Severity CVSS v4.0: Pending analysis
Last modification:
29/04/2019

CVE-2019-11576

Publication date:
28/04/2019
Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, then an attacker could send them to the API without requiring the 2FA one-time password.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-11565

Publication date:
27/04/2019
Server Side Request Forgery (SSRF) exists in the Print My Blog plugin before 1.6.7 for WordPress via the site parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
01/05/2019

CVE-2019-11567

Publication date:
27/04/2019
An issue was discovered in AikCms v2.0. There is a SQL Injection vulnerability via $_GET['del'], as demonstrated by an admin/page/system/nav.php?del= URI.
Severity CVSS v4.0: Pending analysis
Last modification:
29/04/2019

CVE-2019-11568

Publication date:
27/04/2019
An issue was discovered in AikCms v2.0. There is a File upload vulnerability, as demonstrated by an admin/page/system/nav.php request with PHP code in a .php file with the application/octet-stream content type.
Severity CVSS v4.0: Pending analysis
Last modification:
29/04/2019

CVE-2019-11555

Publication date:
26/04/2019
The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate fragmentation reassembly state properly for a case where an unexpected fragment could be received. This could result in process termination due to a NULL pointer dereference (denial of service). This affects eap_server/eap_server_pwd.c and eap_peer/eap_pwd.c.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-11557

Publication date:
26/04/2019
The WebDorado Contact Form Builder plugin before 1.0.69 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.
Severity CVSS v4.0: Pending analysis
Last modification:
27/02/2023

CVE-2019-3844

Publication date:
26/04/2019
It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by the service transient group with the setgid bit set. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the GID will be recycled.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-3843

Publication date:
26/04/2019
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the UID/GID will be recycled.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-11492

Publication date:
26/04/2019
ProjectSend before r1070 writes user passwords to the server logs.
Severity CVSS v4.0: Pending analysis
Last modification:
30/04/2019

CVE-2019-11533

Publication date:
26/04/2019
Cross-site scripting (XSS) vulnerability in ProjectSend before r1070 allows remote attackers to inject arbitrary web script or HTML.
Severity CVSS v4.0: Pending analysis
Last modification:
01/05/2019