Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-2704

Publication date:
02/04/2025
OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase
Severity CVSS v4.0: Pending analysis
Last modification:
23/10/2025

CVE-2025-29085

Publication date:
02/04/2025
SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2024-38392

Publication date:
02/04/2025
Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remote attackers can cause the application to run untrusted code.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2024-37917

Publication date:
02/04/2025
Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a crafted signalling message.
Severity CVSS v4.0: Pending analysis
Last modification:
18/06/2025

CVE-2025-31286

Publication date:
02/04/2025
An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute arbitrary code.<br /> <br /> Please note: this issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
02/09/2025

CVE-2025-31284

Publication date:
02/04/2025
A broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. <br /> <br /> Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
02/09/2025

CVE-2025-31285

Publication date:
02/04/2025
A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. <br /> <br /> Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
02/09/2025

CVE-2025-31283

Publication date:
02/04/2025
A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. <br /> <br /> Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
02/09/2025

CVE-2025-31282

Publication date:
02/04/2025
A broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. <br /> <br /> Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
02/09/2025

CVE-2025-20212

Publication date:
02/04/2025
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series devices could allow an authenticated, remote attacker to cause a denial of service (DoS) condition in the Cisco AnyConnect service on an affected device. To exploit this vulnerability, the attacker must have valid VPN user credentials on the affected device.<br /> <br /> This vulnerability exists because a variable is not initialized when an SSL VPN session is established. An attacker could exploit this vulnerability by supplying crafted attributes while establishing an SSL VPN session with an affected device. A successful exploit could allow the attacker to cause the Cisco AnyConnect VPN server to restart, resulting in the failure of the established SSL VPN sessions and forcing remote users to initiate a new VPN connection and reauthenticate. A sustained attack could prevent new SSL VPN connections from being established.<br /> <br /> Note: When the attack traffic stops, the Cisco AnyConnect VPN server recovers without manual intervention.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2025-20139

Publication date:
02/04/2025
A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.<br /> <br /> This vulnerability is due to improper validation of user-supplied input to chat entry points. An attacker could exploit this vulnerability by sending malicious requests to a messaging chat entry point in the affected application. A successful exploit could allow the attacker to cause the application to stop responding, resulting in a DoS condition. The application may not recover on its own and may need an administrator to manually restart services to recover.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2025

CVE-2025-20203

Publication date:
02/04/2025
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system.<br /> <br /> The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by inserting malicious code into specific data fields in the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid administrative credentials.<br /> <br /> <br /> <br /> {{value}} ["%7b%7bvalue%7d%7d"])}]]
Severity CVSS v4.0: Pending analysis
Last modification:
01/08/2025