Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-68044

Publication date:
05/01/2026
Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2025-13056

Publication date:
05/01/2026
Improper Neutralization of Input During Web Page Generation (XSS or &amp;#39;Cross-site Scripting&amp;#39;) vulnerability in Centreon Infra Monitoring (Administration ACL menu configuration modules) <br /> <br /> allows Stored XSS to users with high privileges.<br /> <br /> This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.15, from 24.04.0 before 24.04.19.
Severity CVSS v4.0: Pending analysis
Last modification:
26/01/2026

CVE-2025-30633

Publication date:
05/01/2026
Improper Neutralization of Special Elements used in an SQL Command (&amp;#39;SQL Injection&amp;#39;) vulnerability in AA-Team Amazon Native Shopping Recommendations allows SQL Injection.This issue affects Amazon Native Shopping Recommendations: from n/a through 1.3.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2025-31044

Publication date:
05/01/2026
Improper Neutralization of Special Elements used in an SQL Command (&amp;#39;SQL Injection&amp;#39;) vulnerability in AA-Team Premium SEO Pack allows SQL Injection.This issue affects Premium SEO Pack: from n/a through 3.3.2.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2025-31046

Publication date:
05/01/2026
Missing Authorization vulnerability in WPvibes AnyWhere Elementor Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyWhere Elementor Pro: from n/a through 2.29.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2025-31047

Publication date:
05/01/2026
Deserialization of Untrusted Data vulnerability in Themify Themify Edmin allows Object Injection.This issue affects Themify Edmin: from n/a through 2.0.0.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2025-31048

Publication date:
05/01/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Themify Shopo allows Upload a Web Shell to a Web Server.This issue affects Shopo: from n/a through 1.1.4.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2025-12519

Publication date:
05/01/2026
Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows Accessing Functionality Not Properly Constrained by ACLs, resulting in Information Disclosure like downtime or acknowledgement configurations. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.15, from 24.04.0 before 24.04.19.
Severity CVSS v4.0: Pending analysis
Last modification:
26/01/2026

CVE-2026-0585

Publication date:
05/01/2026
A security vulnerability has been detected in code-projects Online Product Reservation System 1.0. Impacted is an unknown function of the file /order_view.php of the component GET Parameter Handler. Such manipulation of the argument transaction_id leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Severity CVSS v4.0: MEDIUM
Last modification:
09/01/2026

CVE-2026-0583

Publication date:
05/01/2026
A security flaw has been discovered in code-projects Online Product Reservation System 1.0. This vulnerability affects unknown code of the file app/user/login.php of the component User Login. The manipulation of the argument emailadd results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Severity CVSS v4.0: MEDIUM
Last modification:
09/01/2026

CVE-2026-0584

Publication date:
05/01/2026
A weakness has been identified in code-projects Online Product Reservation System 1.0. This issue affects some unknown processing of the file app/products/left_cart.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Severity CVSS v4.0: MEDIUM
Last modification:
09/01/2026

CVE-2025-68759

Publication date:
05/01/2026
In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> wifi: rtl818x: Fix potential memory leaks in rtl8180_init_rx_ring()<br /> <br /> In rtl8180_init_rx_ring(), memory is allocated for skb packets and DMA<br /> allocations in a loop. When an allocation fails, the previously<br /> successful allocations are not freed on exit.<br /> <br /> Fix that by jumping to err_free_rings label on error, which calls<br /> rtl8180_free_rx_ring() to free the allocations. Remove the free of<br /> rx_ring in rtl8180_init_rx_ring() error path, and set the freed<br /> priv-&gt;rx_buf entry to null, to avoid double free.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026