Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-25228

Publication date:
21/04/2025
A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the product management area in backend.
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2025

CVE-2025-0632

Publication date:
21/04/2025
Local File Inclusion (LFI) vulnerability in a Render function of Formulatrix Rock Maker Web (RMW) allows a remote attacker to obtain sensitive data via arbitrary code execution. A malicious actor could execute malicious scripts to automatically download configuration files in known locations to exfiltrate data including credentials, and with no rate limiting a malicious actor could enumerate the filesystem of the host machine and potentially lead to full host compromise.<br /> <br /> This issue affects Rock Maker Web: from 3.2.1.1 and later
Severity CVSS v4.0: CRITICAL
Last modification:
28/04/2025

CVE-2025-43970

Publication date:
21/04/2025
An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by ensuring that there are 12 bytes or 36 bytes (depending on the address family).
Severity CVSS v4.0: Pending analysis
Last modification:
08/05/2025

CVE-2025-43971

Publication date:
21/04/2025
An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.
Severity CVSS v4.0: Pending analysis
Last modification:
08/05/2025

CVE-2025-43972

Publication date:
21/04/2025
An issue was discovered in GoBGP before 3.35.0. An attacker can cause a crash in the pkg/packet/bgp/bgp.go flowspec parser by sending fewer than 20 bytes in a certain context.
Severity CVSS v4.0: Pending analysis
Last modification:
08/05/2025

CVE-2025-43973

Publication date:
21/04/2025
An issue was discovered in GoBGP before 3.35.0. pkg/packet/rtr/rtr.go does not verify that the input length corresponds to a situation in which all bytes are available for an RTR message.
Severity CVSS v4.0: Pending analysis
Last modification:
08/05/2025

CVE-2025-43966

Publication date:
21/04/2025
libheif before 1.19.6 has a NULL pointer dereference in ImageItem_iden in image-items/iden.cc.
Severity CVSS v4.0: Pending analysis
Last modification:
08/05/2025

CVE-2025-43967

Publication date:
21/04/2025
libheif before 1.19.6 has a NULL pointer dereference in ImageItem_Grid::get_decoder in image-items/grid.cc because a grid image can reference a nonexistent image item.
Severity CVSS v4.0: Pending analysis
Last modification:
08/05/2025

CVE-2025-43962

Publication date:
21/04/2025
In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp has out-of-bounds reads for tag 0x412 processing, related to large w0 or w1 values or the frac and mult calculations.
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2025

CVE-2025-43963

Publication date:
21/04/2025
In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col and split_row values are not checked in 0x041f tag processing.
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2025

CVE-2025-43964

Publication date:
21/04/2025
In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2025

CVE-2025-43961

Publication date:
21/04/2025
In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser.
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2025