Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-54823

Publication date:
31/07/2025
Rejected reason: Not used
Severity CVSS v4.0: Pending analysis
Last modification:
31/07/2025

CVE-2025-8344

Publication date:
31/07/2025
A vulnerability classified as critical has been found in openviglet shio up to 0.3.8. Affected is the function shStaticFileUpload of the file shio-app/src/main/java/com/viglet/shio/api/staticfile/ShStaticFileAPI.java. The manipulation of the argument filename leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity CVSS v4.0: LOW
Last modification:
29/04/2026

CVE-2025-8339

Publication date:
31/07/2025
A vulnerability was found in code-projects Intern Membership Management System 1.0. It has been classified as critical. This affects an unknown part of the file /student_login.php. The manipulation of the argument user_name/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity CVSS v4.0: MEDIUM
Last modification:
29/04/2026

CVE-2025-8340

Publication date:
31/07/2025
A vulnerability was found in code-projects Intern Membership Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file fill_details.php of the component Error Message Handler. The manipulation of the argument email leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity CVSS v4.0: LOW
Last modification:
29/04/2026

CVE-2025-8343

Publication date:
31/07/2025
A vulnerability was found in openviglet shio up to 0.3.8. It has been rated as critical. This issue affects the function shStaticFilePreUpload of the file shio-app/src/main/java/com/viglet/shio/api/staticfile/ShStaticFileAPI.java. The manipulation of the argument fileName leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity CVSS v4.0: LOW
Last modification:
29/04/2026

CVE-2025-49084

Publication date:
31/07/2025
CVE-2025-49084 is a vulnerability in the management console<br /> of Absolute Secure Access prior to version 13.56. Attackers with administrative<br /> access can overwrite policy rules without the requisite permissions. The attack<br /> complexity is low, attack requirements are present, privileges required are<br /> high and no user interaction is required. There is no impact to<br /> confidentiality, the impact to integrity is low, and there is no impact to<br /> availability. The impact to confidentiality and availability of subsequent systems<br /> is high and the impact to the integrity of subsequent systems is low.
Severity CVSS v4.0: MEDIUM
Last modification:
05/08/2025

CVE-2025-54085

Publication date:
31/07/2025
CVE-2025-54085 is a vulnerability in the management console<br /> of Absolute Secure Access prior to version 13.56. Attackers with administrative<br /> access to the console and who have been assigned a certain set of permissions<br /> can bypass those permissions to improperly read or change other settings. The<br /> attack complexity is low, there are no preexisting attack requirements; the<br /> privileges required are high, and there is no user interaction required. The<br /> impact to system confidentiality and integrity is low, there is no impact to<br /> system availability.
Severity CVSS v4.0: MEDIUM
Last modification:
05/08/2025

CVE-2025-8338

Publication date:
31/07/2025
A vulnerability was found in projectworlds Online Admission System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /adminac.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity CVSS v4.0: MEDIUM
Last modification:
29/04/2026

CVE-2025-36039

Publication date:
31/07/2025
IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms,
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2025

CVE-2025-36040

Publication date:
31/07/2025
IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2025

CVE-2025-49082

Publication date:
31/07/2025
CVE-2025-49082 is a vulnerability in the management console<br /> of Absolute Secure Access prior to version 13.56. Attackers with administrative<br /> access to the console and who have been assigned a certain set of permissions<br /> can bypass those permissions to improperly read other settings. The attack<br /> complexity is low, there are no preexisting attack requirements; the privileges<br /> required are high, and there is no user interaction required. The impact to<br /> system confidentiality is low, there is no impact to system availability or<br /> integrity.
Severity CVSS v4.0: MEDIUM
Last modification:
05/08/2025

CVE-2025-49083

Publication date:
31/07/2025
CVE-2025-49083 is a vulnerability in the management console<br /> of Absolute Secure Access after version 12.00 and prior to version 13.56.<br /> Attackers with administrative access to the console can cause unsafe content to<br /> be deserialized and executed in the security context of the console. The attack<br /> complexity is low and there are no attack requirements. Privileges required are<br /> high and there is no user interaction required. The impact to confidentiality<br /> is low, impact to integrity is high and there is no impact to availability. The<br /> impact to the confidentiality and integrity of subsequent systems is low and<br /> there is no subsequent system impact to availability.
Severity CVSS v4.0: HIGH
Last modification:
05/08/2025