Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-44006

Publication date:
03/10/2025
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource.<br /> <br /> We have already fixed the vulnerability in the following version:<br /> Qsync Central 5.0.0.1 ( 2025/07/09 ) and later
Severity CVSS v4.0: HIGH
Last modification:
08/10/2025

CVE-2025-44007

Publication date:
03/10/2025
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource.<br /> <br /> We have already fixed the vulnerability in the following version:<br /> Qsync Central 5.0.0.1 ( 2025/07/09 ) and later
Severity CVSS v4.0: HIGH
Last modification:
08/10/2025

CVE-2025-52653

Publication date:
03/10/2025
HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application. This can allow the execution of unauthorized scripts, potentially resulting in unauthorized actions or access.
Severity CVSS v4.0: Pending analysis
Last modification:
08/10/2025

CVE-2025-46817

Publication date:
03/10/2025
Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to cause an integer overflow and potentially lead to remote code execution The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2.
Severity CVSS v4.0: Pending analysis
Last modification:
27/01/2026

CVE-2024-56804

Publication date:
03/10/2025
An SQL injection vulnerability has been reported to affect Video Station. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands.<br /> <br /> We have already fixed the vulnerability in the following version:<br /> Video Station 5.8.4 and later
Severity CVSS v4.0: MEDIUM
Last modification:
07/10/2025

CVE-2025-33034

Publication date:
03/10/2025
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data.<br /> <br /> We have already fixed the vulnerability in the following version:<br /> Qsync Central 5.0.0.1 ( 2025/07/09 ) and later
Severity CVSS v4.0: MEDIUM
Last modification:
07/10/2025

CVE-2025-33039

Publication date:
03/10/2025
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource.<br /> <br /> We have already fixed the vulnerability in the following version:<br /> Qsync Central 5.0.0.1 ( 2025/07/09 ) and later
Severity CVSS v4.0: HIGH
Last modification:
07/10/2025

CVE-2025-61590

Publication date:
03/10/2025
Cursor is a code editor built for programming with AI. Versions 1.6 and below are vulnerable to Remote Code Execution (RCE) attacks through Visual Studio Code Workspaces. Workspaces allow users to open more than a single folder and save specific settings (pretty similar to .vscode/settings.json) for the folders / project. An untitled workspace is automatically created by VS Code (untitled.code-workspace), which contains all the folders and workspace settings from the user&amp;#39;s current session, opening up an entire new attack vector if the user has a .code-workspace file in path (either untitled created automatically or a saved one). If an attacker is able to hijack the chat context of the victim (such as via a compromised MCP server), they can use prompt injection to make the Cursor Agent write into this file and modify the workspace. This leads to a bypass of CVE-2025-54130 which can lead to RCE by writing to the settings section. This issue is fixed in version 1.7.
Severity CVSS v4.0: Pending analysis
Last modification:
17/10/2025

CVE-2025-61591

Publication date:
03/10/2025
Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication with an untrusted MCP server, an attacker can impersonate a malicious MCP server and return crafted, maliciously injected commands during the interaction process, leading to command injection and potential remote code execution. If chained with an untrusted MCP service via OAuth, this command injection vulnerability could allow arbitrary code execution on the host by the agent. This can then be used to directly compromise the system by executing malicious commands with full user privileges. This issue does not currently have a fixed release version, but there is a patch, 2025.09.17-25b418f.
Severity CVSS v4.0: Pending analysis
Last modification:
17/10/2025

CVE-2025-56551

Publication date:
03/10/2025
An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with arbitrary attacker-controlled content via supplying a crafted GET request.
Severity CVSS v4.0: Pending analysis
Last modification:
15/10/2025

CVE-2021-42193

Publication date:
03/10/2025
nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the product in the shop, the XSS payload fires.
Severity CVSS v4.0: Pending analysis
Last modification:
19/12/2025

CVE-2025-60787

Publication date:
03/10/2025
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to achieve code execution when Motion is restarted.
Severity CVSS v4.0: Pending analysis
Last modification:
10/10/2025