Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-1083

Publication date:
06/02/2025
A vulnerability classified as problematic was found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected by this vulnerability is an unknown functionality of the component CORS Handler. The manipulation leads to permissive cross-domain policy with untrusted domains. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity CVSS v4.0: LOW
Last modification:
06/02/2025

CVE-2025-21267

Publication date:
06/02/2025
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
11/02/2025

CVE-2025-21253

Publication date:
06/02/2025
Microsoft Edge for IOS and Android Spoofing Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
11/02/2025

CVE-2025-21177

Publication date:
06/02/2025
Server-Side Request Forgery (SSRF) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network.
Severity CVSS v4.0: Pending analysis
Last modification:
11/02/2025

CVE-2024-57609

Publication date:
06/02/2025
An issue in Kanaries Inc Pygwalker before v.0.4.9.9 allows a remote attacker to obtain sensitive information and execute arbitrary code via the redirect_path parameter of the login redirection function.
Severity CVSS v4.0: Pending analysis
Last modification:
10/02/2025

CVE-2024-57392

Publication date:
06/02/2025
Buffer Overflow vulnerability in Proftpd commit 4017eff8 allows a remote attacker to execute arbitrary code and can cause a Denial of Service (DoS) on the FTP service by sending a maliciously crafted message to the ProFTPD service port.
Severity CVSS v4.0: Pending analysis
Last modification:
02/03/2025

CVE-2024-53586

Publication date:
06/02/2025
An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a crafted HTTP request. By injecting traversal payloads into the parameter, attackers can manipulate file paths and gain unauthorized access to sensitive files, potentially exposing data outside the intended directory.
Severity CVSS v4.0: Pending analysis
Last modification:
11/02/2025

CVE-2024-55241

Publication date:
06/02/2025
An issue in deep-diver LLM-As-Chatbot before commit 99c2c03 allows a remote attacker to execute arbitrary code via the modelsbyom.py component.
Severity CVSS v4.0: Pending analysis
Last modification:
11/02/2025

CVE-2024-54909

Publication date:
06/02/2025
A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/local/download endpoint, where manipulation of this parameter can lead to arbitrary file download.
Severity CVSS v4.0: Pending analysis
Last modification:
12/02/2025

CVE-2024-56889

Publication date:
06/02/2025
Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers to arbitrarily delete complaints via modification of the id parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
18/04/2025

CVE-2024-25883

Publication date:
06/02/2025
The mstatus register in RSD commit 3d13a updates incorrectly, leading to processing errors.
Severity CVSS v4.0: Pending analysis
Last modification:
10/02/2025

CVE-2024-48589

Publication date:
06/02/2025
Cross Site Scripting vulnerability in Gilnei Moraes phpABook v.0.9 allows a remote attacker to execute arbitrary code via the rol parameter in index.php
Severity CVSS v4.0: Pending analysis
Last modification:
11/02/2025