Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-12463

Publication date:
03/11/2025
An unauthenticated SQL Injection was discovered within the Geutebruck G-Cam E-Series Cameras through the `Group` parameter in the `/uapi-cgi/viewer/Param.cgi` script. This has been confirmed on the EFD-2130 camera running firmware version 1.12.0.19.
Severity CVSS v4.0: Pending analysis
Last modification:
04/11/2025

CVE-2025-11953

Publication date:
03/11/2025
The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.
Severity CVSS v4.0: Pending analysis
Last modification:
11/11/2025

CVE-2025-10280

Publication date:
03/11/2025
IdentityIQ<br /> 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and<br /> all 8.3 patch levels including 8.3p5, and all prior versions allows some<br /> IdentityIQ web services that provide non-HTML content to be accessed via a URL<br /> path that will set the Content-Type to HTML allowing a requesting browser to<br /> interpret content not properly escaped to prevent Cross-Site Scripting (XSS).
Severity CVSS v4.0: Pending analysis
Last modification:
12/11/2025

CVE-2025-63449

Publication date:
03/11/2025
Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /orders.php.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2025

CVE-2025-63453

Publication date:
03/11/2025
Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/contact.php.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2025

CVE-2025-63452

Publication date:
03/11/2025
Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/forgot-pass.php.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2025

CVE-2025-63451

Publication date:
03/11/2025
Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/sign-in.php.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2025

CVE-2025-63450

Publication date:
03/11/2025
Car-Booking-System-PHP v.1.0 is vulnerable to Cross Site Scripting (XSS) in /carlux/booking.php.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2025

CVE-2025-63448

Publication date:
03/11/2025
Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit_product.php?id=1.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2025

CVE-2025-63447

Publication date:
03/11/2025
Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_customer.php.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2025

CVE-2025-63446

Publication date:
03/11/2025
Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_vendor.php.
Severity CVSS v4.0: Pending analysis
Last modification:
10/11/2025

CVE-2025-60503

Publication date:
03/11/2025
A cross-site scripting (XSS) vulnerability exists in the administrative interface of ultimatefosters UltimatePOS 4.8 where input submitted in the purchase functionality is reflected without proper escaping in the admin log panel page in the &amp;#39;reference No.&amp;#39; field. This flaw allows an authenticated attacker to execute arbitrary JavaScript in the context of an administrator&amp;#39;s browser session, which could lead to session hijacking or other malicious actions.
Severity CVSS v4.0: Pending analysis
Last modification:
04/11/2025