Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-60730

Publication date:
24/10/2025
PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function
Severity CVSS v4.0: Pending analysis
Last modification:
24/10/2025

CVE-2025-62714

Publication date:
24/10/2025
Karmada Dashboard is a general-purpose, web-based control panel for Karmada which is a multi-cluster management project. Prior to version 0.2.0, there is an authentication bypass vulnerability in the Karmada Dashboard API. The backend API endpoints (e.g., /api/v1/secret, /api/v1/service) did not enforce authentication, allowing unauthenticated users to access sensitive cluster information such as Secrets and Services directly. Although the web UI required a valid JWT for access, the API itself remained exposed to direct requests without any authentication checks. Any user or entity with network access to the Karmada Dashboard service could exploit this vulnerability to retrieve sensitive data.
Severity CVSS v4.0: HIGH
Last modification:
24/10/2025

CVE-2025-60803

Publication date:
24/10/2025
Antabot White-Jotter up to commit 9bcadc was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the component /api/aaa;/../register.
Severity CVSS v4.0: Pending analysis
Last modification:
24/10/2025

CVE-2025-60801

Publication date:
24/10/2025
jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function.
Severity CVSS v4.0: Pending analysis
Last modification:
24/10/2025

CVE-2025-60566

Publication date:
24/10/2025
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetMACFilter.
Severity CVSS v4.0: Pending analysis
Last modification:
24/10/2025

CVE-2025-60565

Publication date:
24/10/2025
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSchedule.
Severity CVSS v4.0: Pending analysis
Last modification:
24/10/2025

CVE-2025-60564

Publication date:
24/10/2025
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetLog.
Severity CVSS v4.0: Pending analysis
Last modification:
24/10/2025

CVE-2025-60563

Publication date:
24/10/2025
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetPortTr.
Severity CVSS v4.0: Pending analysis
Last modification:
24/10/2025

CVE-2025-60562

Publication date:
24/10/2025
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formWlSiteSurvey.
Severity CVSS v4.0: Pending analysis
Last modification:
24/10/2025

CVE-2025-60561

Publication date:
24/10/2025
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetEmail.
Severity CVSS v4.0: Pending analysis
Last modification:
24/10/2025

CVE-2025-60559

Publication date:
24/10/2025
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetDomainFilter.
Severity CVSS v4.0: Pending analysis
Last modification:
24/10/2025

CVE-2025-60554

Publication date:
24/10/2025
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetEnableWizard.
Severity CVSS v4.0: Pending analysis
Last modification:
24/10/2025