Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-2416

Publication date:
03/09/2025
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft LimonDesk allows Authentication Bypass.This issue affects LimonDesk: from s1.02.14 before v1.02.17.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2025

CVE-2025-0878

Publication date:
03/09/2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft LimonDesk allows Cross-Site Scripting (XSS).This issue affects LimonDesk: from s1.02.14 before v1.02.17.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2025

CVE-2024-13068

Publication date:
03/09/2025
Origin Validation Error vulnerability in Akinsoft LimonDesk allows Forceful Browsing.This issue affects LimonDesk: from s1.02.14 before v1.02.17.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2025

CVE-2025-9901

Publication date:
03/09/2025
A flaw was found in libsoup’s caching mechanism, SoupCache, where the HTTP Vary header is ignored when evaluating cached responses. This header ensures that responses vary appropriately based on request headers such as language or authentication. Without this check, cached content can be incorrectly reused across different requests, potentially exposing sensitive user information. While the issue is unlikely to affect everyday desktop use, it could result in confidentiality breaches in proxy or multi-user environments.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2025

CVE-2025-3701

Publication date:
03/09/2025
Missing Authorization vulnerability in Malcure Web Security Malcure Malware Scanner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Malcure Malware Scanner: from n/a through 16.8.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2025

CVE-2025-53691

Publication date:
03/09/2025
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (RCE).This issue affects Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform (XP): from 9.0 through 9.3, from 10.0 through 10.4.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2025

CVE-2025-53693

Publication date:
03/09/2025
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cache Poisoning.This issue affects Sitecore Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform (XP): from 9.0 through 9.3, from 10.0 through 10.4.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2025

CVE-2025-53694

Publication date:
03/09/2025
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Experience Platform (XP): from 9.2 through 10.4.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2025

CVE-2025-38678

Publication date:
03/09/2025
In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> netfilter: nf_tables: reject duplicate device on updates<br /> <br /> A chain/flowtable update with duplicated devices in the same batch is<br /> possible. Unfortunately, netdev event path only removes the first<br /> device that is found, leaving unregistered the hook of the duplicated<br /> device.<br /> <br /> Check if a duplicated device exists in the transaction batch, bail out<br /> with EEXIST in such case.<br /> <br /> WARNING is hit when unregistering the hook:<br /> <br /> [49042.221275] WARNING: CPU: 4 PID: 8425 at net/netfilter/core.c:340 nf_hook_entry_head+0xaa/0x150<br /> [49042.221375] CPU: 4 UID: 0 PID: 8425 Comm: nft Tainted: G S 6.16.0+ #170 PREEMPT(full)<br /> [...]<br /> [49042.221382] RIP: 0010:nf_hook_entry_head+0xaa/0x150
Severity CVSS v4.0: Pending analysis
Last modification:
06/12/2025

CVE-2024-13066

Publication date:
03/09/2025
Improper Restriction of Rendered UI Layers or Frames vulnerability in Akinsoft LimonDesk allows iFrame Overlay, CAPEC - 103 - Clickjacking.This issue affects LimonDesk: from s1.02.14 before v1.02.17.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2025

CVE-2025-41000

Publication date:
03/09/2025
Cross-Frame Scripting (XFS) vulnerability in BoomCMS v9.1.4 from UXB London. XFS is a web attack technique that exploits specific browser bugs to spy on users via JavaScript. This type of attack is based on social engineering and depends entirely on the browser chosen by the user, so it is perceived as a minor threat to web application security. This vulnerability only works in older browsers.
Severity CVSS v4.0: LOW
Last modification:
04/09/2025

CVE-2025-9821

Publication date:
03/09/2025
SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed<br /> <br /> DetailsWhen sending webhooks, the destination is not validated, causing SSRF.<br /> <br /> <br /> ImpactBypass of firewalls to interact with internal services.<br /> See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/  for more potential impact.<br /> <br /> Resources https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html  for more information on SSRF and its fix.
Severity CVSS v4.0: Pending analysis
Last modification:
04/09/2025