Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-24185

Publication date:
17/03/2025
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. Parsing a maliciously crafted file may lead to an unexpected app termination.
Severity CVSS v4.0: Pending analysis
Last modification:
02/04/2026

CVE-2025-0495

Publication date:
17/03/2025
Buildx is a Docker CLI plugin that extends build capabilities using BuildKit.<br /> <br /> Cache backends support credentials by setting secrets directly as attribute values in cache-to/cache-from configuration. When supplied as user input, these secure values may be inadvertently captured in OpenTelemetry traces as part of the arguments and flags for the traced CLI command. OpenTelemetry traces are also saved in BuildKit daemon&amp;#39;s history records.<br /> <br /> <br /> This vulnerability does not impact secrets passed to the Github cache backend via environment variables or registry authentication.
Severity CVSS v4.0: MEDIUM
Last modification:
15/04/2026

CVE-2025-2390

Publication date:
17/03/2025
A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. This affects an unknown part of the file /user_dashboard/add_donor.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity CVSS v4.0: MEDIUM
Last modification:
02/04/2025

CVE-2025-29427

Publication date:
17/03/2025
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in profile.php via the member_first and member_last parameters.
Severity CVSS v4.0: Pending analysis
Last modification:
23/10/2025

CVE-2025-2389

Publication date:
17/03/2025
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add_city.php. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity CVSS v4.0: MEDIUM
Last modification:
23/10/2025

CVE-2025-29425

Publication date:
17/03/2025
Code-projects Online Class and Exam Scheduling System 1.0 is vulnerable to SQL Injection in exam_save.php via the parameters member and first.
Severity CVSS v4.0: Pending analysis
Last modification:
23/10/2025

CVE-2025-26042

Publication date:
17/03/2025
Uptime Kuma &gt;== 1.23.0 has a ReDoS vulnerability, specifically when an administrator creates a notification through the web service. If a string is provided it triggers catastrophic backtracking in the regular expression, leading to a ReDoS attack.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2024-8510

Publication date:
17/03/2025
N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Customer data is not exposed. <br /> <br /> This vulnerability is present in all deployments of N-central prior to N-central 2024.6.
Severity CVSS v4.0: Pending analysis
Last modification:
05/09/2025

CVE-2024-44866

Publication date:
17/03/2025
A buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via opening a crafted GuitarPro file.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2025-29429

Publication date:
17/03/2025
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/program.php via the id, code, and name parameters.
Severity CVSS v4.0: Pending analysis
Last modification:
23/10/2025

CVE-2025-29430

Publication date:
17/03/2025
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/room.php via the id and rome parameters.
Severity CVSS v4.0: Pending analysis
Last modification:
23/10/2025

CVE-2025-2387

Publication date:
17/03/2025
A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been classified as critical. Affected is an unknown function of the file /admin/ajax.php?action=add_to_cart. The manipulation of the argument pid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity CVSS v4.0: MEDIUM
Last modification:
28/05/2025