Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-0690

Publication date:
15/11/2018
An unvalidated software update vulnerability in Music Center for PC version 1.0.02 and earlier could allow a man-in-the-middle attacker to tamper with an update file and inject executable files.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-0679

Publication date:
15/11/2018
Cross-site scripting vulnerability in multiple FXC Inc. network devices (Managed Ethernet switch FXC5210/5218/5224 firmware prior to version Ver1.00.22, Managed Ethernet switch FXC5426F firmware prior to version Ver1.00.06, Managed Ethernet switch FXC5428 firmware prior to version Ver1.00.07, Power over Ethernet (PoE) switch FXC5210PE/5218PE/5224PE firmware prior to version Ver1.00.14, and Wireless LAN router AE1021/AE1021PE firmware all versions) allows attacker with administrator rights to inject arbitrary web script or HTML via the administrative page.
Severity CVSS v4.0: Pending analysis
Last modification:
31/12/2018

CVE-2018-12480

Publication date:
15/11/2018
Mitigates an XSS issue in NetIQ Access Manager versions prior to 4.4 SP3.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2018-19291

Publication date:
15/11/2018
An issue was discovered in DiliCMS 2.4.0. There is a CSRF vulnerability that can delete a user or group via an admin/index.php/user/del/1 or admin/index.php/role/del/2 URI.
Severity CVSS v4.0: Pending analysis
Last modification:
16/04/2019

CVE-2018-19287

Publication date:
15/11/2018
XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
14/12/2018

CVE-2015-9274

Publication date:
15/11/2018
HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (invalid read of two bytes and application crash) because of GPOS and GSUB table mishandling, related to hb-ot-layout-gpos-table.hh, hb-ot-layout-gsub-table.hh, and hb-ot-layout-gsubgpos-private.hh.
Severity CVSS v4.0: Pending analysis
Last modification:
18/12/2018

CVE-2018-19289

Publication date:
15/11/2018
An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2018-19286

Publication date:
15/11/2018
The server in mubu note 2018-11-11 has XSS by configuring an account with a crafted name value (along with an arbitrary username value), and then creating and sharing a note.
Severity CVSS v4.0: Pending analysis
Last modification:
25/06/2020

CVE-2018-19288

Publication date:
15/11/2018
Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API.
Severity CVSS v4.0: Pending analysis
Last modification:
04/05/2021

CVE-2018-19279

Publication date:
14/11/2018
PRIMX ZoneCentral before 6.1.2236 on Windows sometimes leaks the plaintext of NTFS files. On non-SSD devices, this is limited to a 5-second window and file sizes less than 600 bytes. The effect on SSD devices may be greater.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-19280

Publication date:
14/11/2018
Centreon 3.4.x (fixed in Centreon 18.10.0) has XSS via the resource name or macro expression of a poller macro.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2019

CVE-2018-19281

Publication date:
14/11/2018
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2019