Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-23504

Publication date:
08/01/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in RiceTheme Felan Framework felan-framework allows Authentication Abuse.This issue affects Felan Framework: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2026

CVE-2025-23993

Publication date:
08/01/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RiceTheme Felan Framework felan-framework allows SQL Injection.This issue affects Felan Framework: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2026

CVE-2025-27002

Publication date:
08/01/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup CountDown With Image or Video Background countdown-with-background allows Reflected XSS.This issue affects CountDown With Image or Video Background: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2026

CVE-2025-27004

Publication date:
08/01/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Famous - Responsive Image And Video Grid Gallery WordPress Plugin famous_grid_image_and_video_gallery allows Reflected XSS.This issue affects Famous - Responsive Image And Video Grid Gallery WordPress Plugin: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2026

CVE-2025-22509

Publication date:
08/01/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TMRW-studio Atlas atlas allows PHP Local File Inclusion.This issue affects Atlas: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2026

CVE-2025-22707

Publication date:
08/01/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Moody tm-moody allows PHP Local File Inclusion.This issue affects Moody: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2026

CVE-2025-22708

Publication date:
08/01/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Mitech mitech allows PHP Local File Inclusion.This issue affects Mitech: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2026

CVE-2025-22712

Publication date:
08/01/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in QantumThemes Typify typify allows PHP Local File Inclusion.This issue affects Typify: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2026

CVE-2025-22713

Publication date:
08/01/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vanquish WooCommerce Orders & Customers Exporter woocommerce-orders-ei allows SQL Injection.This issue affects WooCommerce Orders & Customers Exporter: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2026

CVE-2025-22715

Publication date:
08/01/2026
Missing Authorization vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_AttractiveDonationsSystem allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Attractive Donations System - Easy Stripe & Paypal donations: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2026

CVE-2025-15079

Publication date:
08/01/2026
When doing SSH-based transfers using either SCP or SFTP, and setting the<br /> known_hosts file, libcurl could still mistakenly accept connecting to hosts<br /> *not present* in the specified file if they were added as recognized in the<br /> libssh *global* known_hosts file.
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2026

CVE-2025-15224

Publication date:
08/01/2026
When doing SSH-based transfers using either SCP or SFTP, and asked to do<br /> public key authentication, curl would wrongly still ask and authenticate using<br /> a locally running SSH agent.
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2026