Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-32910

Publication date:
14/04/2025
A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This issue may cause the libsoup client to crash.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2025-32912

Publication date:
14/04/2025
A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2025-32914

Publication date:
14/04/2025
A flaw was found in libsoup, where the soup_multipart_new_from_message() function is vulnerable to an out-of-bounds read. This flaw allows a malicious HTTP client to induce the libsoup server to read out of bounds.
Severity CVSS v4.0: Pending analysis
Last modification:
22/04/2026

CVE-2025-2160

Publication date:
14/04/2025
Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup
Severity CVSS v4.0: Pending analysis
Last modification:
30/10/2025

CVE-2025-2161

Publication date:
14/04/2025
Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup
Severity CVSS v4.0: Pending analysis
Last modification:
30/10/2025

CVE-2025-2424

Publication date:
14/04/2025
Mattermost versions 10.5.x
Severity CVSS v4.0: Pending analysis
Last modification:
01/10/2025

CVE-2025-2475

Publication date:
14/04/2025
Mattermost versions 10.5.x
Severity CVSS v4.0: Pending analysis
Last modification:
02/10/2025

CVE-2024-49825

Publication date:
14/04/2025
IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.20 and 23.0.0 through 23.0.20 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.
Severity CVSS v4.0: Pending analysis
Last modification:
19/08/2025

CVE-2025-3568

Publication date:
14/04/2025
A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/settings/users/edit/ of the component SVG File Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor prepares a fix for the next major release and explains that he does not think therefore that this should qualify for a CVE.
Severity CVSS v4.0: MEDIUM
Last modification:
26/06/2025

CVE-2025-3569

Publication date:
14/04/2025
A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file ShiroConfig.java. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity CVSS v4.0: MEDIUM
Last modification:
10/02/2026

CVE-2025-32906

Publication date:
14/04/2025
A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. This flaw allows a malicious user to use a specially crafted HTTP request to crash the HTTP server.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2025-32907

Publication date:
14/04/2025
A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026