Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-69299

Publication date:
20/02/2026
Server-Side Request Forgery (SSRF) vulnerability in Laborator Oxygen oxygen allows Server Side Request Forgery.This issue affects Oxygen: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
24/02/2026

CVE-2025-69301

Publication date:
20/02/2026
Deserialization of Untrusted Data vulnerability in ThemeGoods PhotoMe photome allows Object Injection.This issue affects PhotoMe: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
24/02/2026

CVE-2025-69297

Publication date:
20/02/2026
Missing Authorization vulnerability in GhostPool Aardvark Plugin aardvark-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Aardvark Plugin: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
24/02/2026

CVE-2025-69295

Publication date:
20/02/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Coven Core coven-core allows Blind SQL Injection.This issue affects Coven Core: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
24/02/2026

CVE-2025-69296

Publication date:
20/02/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhostPool Aardvark aardvark allows Reflected XSS.This issue affects Aardvark: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
23/02/2026

CVE-2025-69298

Publication date:
20/02/2026
Missing Authorization vulnerability in GhostPool Gauge gauge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gauge: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
25/02/2026

CVE-2025-69063

Publication date:
20/02/2026
Missing Authorization vulnerability in Saad Iqbal New User Approve new-user-approve allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects New User Approve: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
24/02/2026

CVE-2025-69294

Publication date:
20/02/2026
Deserialization of Untrusted Data vulnerability in fuelthemes PeakShops peakshops allows Object Injection.This issue affects PeakShops: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
24/02/2026

CVE-2025-69011

Publication date:
20/02/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKube Cool Tag Cloud cool-tag-cloud allows Stored XSS.This issue affects Cool Tag Cloud: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
25/02/2026

CVE-2025-68880

Publication date:
20/02/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in peterwsterling Simple Archive Generator simple-archive-generator allows Reflected XSS.This issue affects Simple Archive Generator: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
23/02/2026

CVE-2025-68895

Publication date:
20/02/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in ahachat AhaChat Messenger Marketing ahachat-messenger-marketing allows Password Recovery Exploitation.This issue affects AhaChat Messenger Marketing: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
27/02/2026

CVE-2025-68863

Publication date:
20/02/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zack Katz iContact for Gravity Forms gravity-forms-icontact allows Reflected XSS.This issue affects iContact for Gravity Forms: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
23/02/2026