Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-19286

Publication date:
15/11/2018
The server in mubu note 2018-11-11 has XSS by configuring an account with a crafted name value (along with an arbitrary username value), and then creating and sharing a note.
Severity CVSS v4.0: Pending analysis
Last modification:
25/06/2020

CVE-2018-19288

Publication date:
15/11/2018
Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API.
Severity CVSS v4.0: Pending analysis
Last modification:
04/05/2021

CVE-2018-19279

Publication date:
14/11/2018
PRIMX ZoneCentral before 6.1.2236 on Windows sometimes leaks the plaintext of NTFS files. On non-SSD devices, this is limited to a 5-second window and file sizes less than 600 bytes. The effect on SSD devices may be greater.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-19280

Publication date:
14/11/2018
Centreon 3.4.x (fixed in Centreon 18.10.0) has XSS via the resource name or macro expression of a poller macro.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2019

CVE-2018-19281

Publication date:
14/11/2018
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2019

CVE-2018-19278

Publication date:
14/11/2018
Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 16.0.1 allows remote attackers to crash Asterisk via a specially crafted DNS SRV or NAPTR response, because a buffer size is supposed to match an expanded length but actually matches a compressed length.
Severity CVSS v4.0: Pending analysis
Last modification:
30/12/2018

CVE-2018-17960

Publication date:
14/11/2018
CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2019

CVE-2018-5495

Publication date:
14/11/2018
All StorageGRID Webscale versions are susceptible to a vulnerability which could permit an unauthenticated attacker to communicate with systems on the same network as the StorageGRID Webscale Admin Node via HTTP or to take over services on the Admin Node.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-9542

Publication date:
14/11/2018
In avrc_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-111896861
Severity CVSS v4.0: Pending analysis
Last modification:
17/12/2018

CVE-2018-9544

Publication date:
14/11/2018
In register_app of btif_hd.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113037220
Severity CVSS v4.0: Pending analysis
Last modification:
17/12/2018

CVE-2018-9545

Publication date:
14/11/2018
In BTA_HdRegisterApp of bta_hd_api.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113111784
Severity CVSS v4.0: Pending analysis
Last modification:
17/12/2018

CVE-2018-9543

Publication date:
14/11/2018
In trim_device of f2fs_format_utils.c, it is possible that the data partition is not wiped during a factory reset. This could lead to local information disclosure after factory reset with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-112868088.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019