Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-23115

Publication date:
01/03/2025
A Use After Free vulnerability on UniFi Protect Cameras could allow a Remote Code Execution (RCE) by a malicious actor with access to UniFi Protect Cameras management network.
Severity CVSS v4.0: Pending analysis
Last modification:
13/03/2025

CVE-2025-23116

Publication date:
01/03/2025
An Authentication Bypass vulnerability on UniFi Protect Application with Auto-Adopt Bridge Devices enabled could allow a malicious actor with access to UniFi Protect Cameras adjacent network to take control of UniFi Protect Cameras.
Severity CVSS v4.0: Pending analysis
Last modification:
04/03/2025

CVE-2025-23117

Publication date:
01/03/2025
An Insufficient Firmware Update Validation vulnerability could allow an authenticated malicious actor with access to UniFi Protect Cameras adjacent network to make unsupported changes to the camera system.
Severity CVSS v4.0: Pending analysis
Last modification:
05/03/2025

CVE-2025-23118

Publication date:
01/03/2025
An Improper Certificate Validation vulnerability could allow an authenticated malicious actor with access to UniFi Protect Cameras adjacent network to make unsupported changes to the camera system.
Severity CVSS v4.0: Pending analysis
Last modification:
04/03/2025

CVE-2025-1803

Publication date:
01/03/2025
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.
Severity CVSS v4.0: Pending analysis
Last modification:
01/03/2025

CVE-2025-27416

Publication date:
01/03/2025
Scratch-Coding-Hut.github.io is the website for Coding Hut. The website as of 28 February 2025 contained a sign in with scratch username and password form. Any user who used the sign in page would be susceptible to any other user signing into their account. As of time of publication, a fix is not available but work on a fix is underway. As a workaround, users should avoid signing in.
Severity CVSS v4.0: MEDIUM
Last modification:
01/03/2025

CVE-2025-25723

Publication date:
28/02/2025
Buffer Overflow vulnerability in GPAC version 2.5 allows a local attacker to execute arbitrary code.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2025-25478

Publication date:
28/02/2025
The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web application s source code, exposing sensitive information such as the database password.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2025

CVE-2025-25476

Publication date:
28/02/2025
A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Javascript code by specifying a malicious XSS payload as a notification type or notification component.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2025

CVE-2025-25379

Publication date:
28/02/2025
Cross Site Request Forgery vulnerability in 07FLYCMS v.1.3.9 allows a remote attacker to execute arbitrary code via the id parameter of the del.html component.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2025

CVE-2025-26466

Publication date:
28/02/2025
A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. Consequently, the server may become unavailable, resulting in a denial of service attack.
Severity CVSS v4.0: Pending analysis
Last modification:
27/05/2025

CVE-2024-1509

Publication date:
28/02/2025
Brocade ASCG before 3.2.0 Web Interface is not <br /> enforcing HSTS, as defined by RFC 6797. HSTS is an optional response <br /> header that can be configured on the server to instruct the browser to <br /> only communicate via HTTPS. The lack of HSTS allows downgrade attacks, <br /> SSL-stripping man-in-the-middle attacks, and weakens cookie-hijacking <br /> protections.
Severity CVSS v4.0: HIGH
Last modification:
28/02/2025