Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-69327

Publication date:
06/01/2026
Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Rental Manager: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2026

CVE-2025-69331

Publication date:
06/01/2026
Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Theater for WordPress: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2026

CVE-2025-47553

Publication date:
06/01/2026
Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery: from n/a through 12.25.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2026

CVE-2025-63082

Publication date:
06/01/2026
Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.
Severity CVSS v4.0: MEDIUM
Last modification:
06/01/2026

CVE-2025-63083

Publication date:
06/01/2026
Lack of output escaping leads to a XSS vector in the pagebreak plugin.
Severity CVSS v4.0: MEDIUM
Last modification:
06/01/2026

CVE-2025-60534

Publication date:
06/01/2026
Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests in order to operate functionality on the web application without the need to authenticate with legitimate credentials.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2026

CVE-2025-36589

Publication date:
06/01/2026
Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data and resources outside of the intended sphere of control.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2026

CVE-2025-39477

Publication date:
06/01/2026
Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InWave Jobs: from n/a through 3.5.8.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2026

CVE-2024-31088

Publication date:
06/01/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPShop.Ru AdsPlace'r – Ad Manager, Inserter, AdSense Ads allows DOM-Based XSS.This issue affects AdsPlace'r – Ad Manager, Inserter, AdSense Ads: from n/a through 1.1.5.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2026

CVE-2024-30547

Publication date:
06/01/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Shazdeh Header Image Slider header-image-slider allows DOM-Based XSS.This issue affects Header Image Slider: from n/a through 0.3.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2026

CVE-2026-0640

Publication date:
06/01/2026
A weakness has been identified in Tenda AC23 16.03.07.52. This affects the function sscanf of the file /goform/PowerSaveSet. Executing a manipulation of the argument Time can lead to buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
Severity CVSS v4.0: HIGH
Last modification:
06/01/2026

CVE-2025-14979

Publication date:
06/01/2026
AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.This issue affects Eddie: 2.24.6.
Severity CVSS v4.0: HIGH
Last modification:
06/01/2026