Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-25713

Publication date:
29/02/2024
yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part of the pool series allocator, along with pool_malloc and pool_realloc.)
Severity CVSS v4.0: Pending analysis
Last modification:
04/11/2025

CVE-2024-25830

Publication date:
29/02/2024
F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the configuration file. A successful exploit could allow the attacker to extract the root and admin password.
Severity CVSS v4.0: Pending analysis
Last modification:
10/06/2025

CVE-2024-25831

Publication date:
29/02/2024
F-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input sanitization. An authenticated, remote attacker can execute arbitrary JavaScript code in the web management interface.
Severity CVSS v4.0: Pending analysis
Last modification:
16/01/2025

CVE-2024-25832

Publication date:
29/02/2024
F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension.
Severity CVSS v4.0: Pending analysis
Last modification:
27/03/2025

CVE-2024-25833

Publication date:
29/02/2024
F-logic DataCube3 v1.0 is vulnerable to unauthenticated SQL injection, which could allow an unauthenticated malicious actor to execute arbitrary SQL queries in database.
Severity CVSS v4.0: Pending analysis
Last modification:
16/01/2025

CVE-2024-25262

Publication date:
29/02/2024
texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted TTF file.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2024-25006

Publication date:
29/02/2024
XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.
Severity CVSS v4.0: Pending analysis
Last modification:
08/05/2025

CVE-2024-25065

Publication date:
29/02/2024
Possible path traversal in Apache OFBiz allowing authentication bypass.<br /> Users are recommended to upgrade to version 18.12.12, that fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2025

CVE-2024-25128

Publication date:
29/02/2024
Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, it allows an attacker to forge an HTTP request, that could deceive the backend into using any requested OpenID service. This vulnerability could grant an attacker unauthorised privilege access if a custom OpenID service is deployed by the attacker and accessible by the backend. This vulnerability is only exploitable when the application is using the OpenID 2.0 authorization protocol. Upgrade to Flask-AppBuilder 4.3.11 to fix the vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
14/10/2025

CVE-2024-24701

Publication date:
29/02/2024
Cross-Site Request Forgery (CSRF) vulnerability in Native Grid LLC A no-code page builder for beautiful performance-based content.This issue affects A no-code page builder for beautiful performance-based content: from n/a through 2.1.20.
Severity CVSS v4.0: Pending analysis
Last modification:
28/04/2026

CVE-2024-24708

Publication date:
29/02/2024
Cross-Site Request Forgery (CSRF) vulnerability in W3speedster W3SPEEDSTER.This issue affects W3SPEEDSTER: from n/a through 7.19.
Severity CVSS v4.0: Pending analysis
Last modification:
28/04/2026

CVE-2024-23946

Publication date:
29/02/2024
Possible path traversal in Apache OFBiz allowing file inclusion.<br /> Users are recommended to upgrade to version 18.12.12, that fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
13/08/2024