Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-64242

Publication date:
16/12/2025
Missing Authorization vulnerability in Merv Barrett Easy Property Listings easy-property-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Property Listings: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
16/12/2025

CVE-2025-64237

Publication date:
16/12/2025
Cross-Site Request Forgery (CSRF) vulnerability in Graham Quick Interest Slider quick-interest-slider allows Cross Site Request Forgery.This issue affects Quick Interest Slider: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
16/12/2025

CVE-2025-64239

Publication date:
16/12/2025
Cross-Site Request Forgery (CSRF) vulnerability in Yoav Farhi RTL Tester rtl-tester allows Cross Site Request Forgery.This issue affects RTL Tester: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
16/12/2025

CVE-2025-64243

Publication date:
16/12/2025
Missing Authorization vulnerability in e-plugins Directory Pro directory-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directory Pro: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
16/12/2025

CVE-2025-64240

Publication date:
16/12/2025
Cross-Site Request Forgery (CSRF) vulnerability in freshchat Freshchat freshchat allows Cross Site Request Forgery.This issue affects Freshchat: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
16/12/2025

CVE-2025-54004

Publication date:
16/12/2025
Missing Authorization vulnerability in WC Lovers WCFM – Frontend Manager for WooCommerce wc-frontend-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCFM – Frontend Manager for WooCommerce: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
16/12/2025

CVE-2025-54005

Publication date:
16/12/2025
Missing Authorization vulnerability in sonalsinha21 SKT Page Builder skt-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SKT Page Builder: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
16/12/2025

CVE-2025-49300

Publication date:
16/12/2025
Insertion of Sensitive Information Into Sent Data vulnerability in shinetheme Traveler Option Tree custom-option-tree allows Retrieve Embedded Sensitive Data.This issue affects Traveler Option Tree: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
16/12/2025

CVE-2025-54045

Publication date:
16/12/2025
Missing Authorization vulnerability in CreativeMindsSolutions CM On Demand Search And Replace cm-on-demand-search-and-replace allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CM On Demand Search And Replace: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
16/12/2025

CVE-2025-59001

Publication date:
16/12/2025
Missing Authorization vulnerability in ThemeNectar Salient Core salient-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salient Core: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
16/12/2025

CVE-2025-58999

Publication date:
16/12/2025
Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_AttractiveDonationsSystem allows Cross Site Request Forgery.This issue affects WP Attractive Donations System - Easy Stripe & Paypal donations: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
16/12/2025

CVE-2025-59009

Publication date:
16/12/2025
Cross-Site Request Forgery (CSRF) vulnerability in Astoundify Listify listify allows Cross Site Request Forgery.This issue affects Listify: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
16/12/2025