Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-9279

Publication date:
20/01/2026
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limit Storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.
Severity CVSS v4.0: HIGH
Last modification:
20/01/2026

CVE-2025-14027

Publication date:
20/01/2026
Multiple denial-of-service vulnerabilities exist in the affected product. These issues can be triggered through various crafted inputs, including malformed Class 3 messages, memory leak conditions, and other resource exhaustion scenarios. Exploitation may cause the device to become unresponsive and, in some cases, result in a major nonrecoverable fault. Recovery may require a restart.
Severity CVSS v4.0: HIGH
Last modification:
20/01/2026

CVE-2025-14376

Publication date:
20/01/2026
A security issue was discovered within the legacy ADI server component of Verve Asset Manager, caused by plaintext secrets stored in environment variables on the ADI server. This component has been retired and has been optional since the 1.36 release in 2024.
Severity CVSS v4.0: HIGH
Last modification:
20/01/2026

CVE-2025-14377

Publication date:
20/01/2026
A security issue was discovered within the legacy Ansible playbook component of Verve Asset Manager, caused by plaintext secrets incorrectly stored when a playbook is running. This component has been retired and has been optional since the 1.36 release in 2024.
Severity CVSS v4.0: HIGH
Last modification:
20/01/2026

CVE-2025-15281

Publication date:
20/01/2026
Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.
Severity CVSS v4.0: Pending analysis
Last modification:
20/01/2026

CVE-2025-11743

Publication date:
20/01/2026
A denial-of-service security issue in the affected product. The security issue occurs when a malformed CIP forward open message is sent. This could result in a major nonrecoverable fault a restart is required to recover.
Severity CVSS v4.0: HIGH
Last modification:
20/01/2026

CVE-2026-1180

Publication date:
20/01/2026
A flaw was identified in Keycloak’s OpenID Connect Dynamic Client Registration feature when clients authenticate using private_key_jwt. The issue allows a client to specify an arbitrary jwks_uri, which Keycloak then retrieves without validating the destination. This enables attackers to coerce the Keycloak server into making HTTP requests to internal or restricted network resources. As a result, attackers can probe internal services and cloud metadata endpoints, creating an information disclosure and reconnaissance risk.
Severity CVSS v4.0: Pending analysis
Last modification:
20/01/2026

CVE-2026-1183

Publication date:
20/01/2026
HTML injection vulnerability in multiple Botble products such as TransP, Athena, Martfury, and Homzen, consisting of an HTML injection due to a lack of proper validation of user input by sending a request to '/search' using the 'q' parameter.
Severity CVSS v4.0: MEDIUM
Last modification:
20/01/2026

CVE-2025-41025

Publication date:
20/01/2026
Stored Cross-Site Scripting (XSS) in Poultry Farm Management System v1.0 due to the lack of proper validation of user input by sending a POST request. The relationship between parameters and assigned identifiers is as follows:  <br /> <br /> &amp;#39;category&amp;#39; y &amp;#39;product&amp;#39; parameters in &amp;#39;/farm/sell_product.php&amp;#39;.
Severity CVSS v4.0: MEDIUM
Last modification:
20/01/2026

CVE-2025-41081

Publication date:
20/01/2026
Reflected Cross-Site Scripting (XSS) vulnerability in IsMyGym by Zuinq Studio. This vulnerability allows an attacker to execute JavaScript code in the victim&amp;#39;s browser by sending them a malicious URL with &amp;#39;/.php/&amp;#39;. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
Severity CVSS v4.0: MEDIUM
Last modification:
20/01/2026

CVE-2025-40644

Publication date:
20/01/2026
Reflected Cross-Site Scripting (XSS) vulnerability in Riftzilla&amp;#39;s QRGen. This vulnerability allows an attavker to execute JavaScript code in the victim&amp;#39;s browser by sending them a malicious URL using the &amp;#39;id&amp;#39; parameter in &amp;#39;/article.php&amp;#39;. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
Severity CVSS v4.0: MEDIUM
Last modification:
20/01/2026

CVE-2025-40679

Publication date:
20/01/2026
HTML <br /> <br /> Injection vulnerability in Isshue by Bdtask, consisting os an HTML injection due to a lack os proper validation of user input by sending a POST request to &amp;#39;/category_product_search&amp;#39;, affecting the &amp;#39;product_name&amp;#39; parameter.
Severity CVSS v4.0: MEDIUM
Last modification:
20/01/2026