Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-55277

Publication date:
26/03/2026
HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability using which an attacker may make use of the exploits available across the internet and craft attacks against the application.
Severity CVSS v4.0: Pending analysis
Last modification:
26/03/2026

CVE-2025-55268

Publication date:
26/03/2026
HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume server bandwidth and processing resources which may lead to Denial of Service.
Severity CVSS v4.0: Pending analysis
Last modification:
26/03/2026

CVE-2025-55269

Publication date:
26/03/2026
HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force techniques to gain unauthorized access to user accounts.
Severity CVSS v4.0: Pending analysis
Last modification:
26/03/2026

CVE-2025-55270

Publication date:
26/03/2026
HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as XSS, SQL Injection, Command Injection etc.
Severity CVSS v4.0: Pending analysis
Last modification:
26/03/2026

CVE-2025-55271

Publication date:
26/03/2026
HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability where in depending on how the web application handles the split response, an attacker may be able to execute arbitrary commands or inject harmful content into the response..
Severity CVSS v4.0: Pending analysis
Last modification:
26/03/2026

CVE-2025-55272

Publication date:
26/03/2026
HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights into the system’s software and version details which would allow them to craft software specific attacks.
Severity CVSS v4.0: Pending analysis
Last modification:
26/03/2026

CVE-2025-55273

Publication date:
26/03/2026
HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts can tamper with the DOM, altering the content or behavior of the application. Malicious scripts can steal cookies or session tokens, leading to session hijacking.
Severity CVSS v4.0: Pending analysis
Last modification:
26/03/2026

CVE-2025-41027

Publication date:
26/03/2026
Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaScript code in the victim's browser by sending a malicious URL in 'site' parameter in 'app_recuperarclave.php'.
Severity CVSS v4.0: MEDIUM
Last modification:
27/03/2026

CVE-2025-41359

Publication date:
26/03/2026
Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable located at 'C:\Program Files (x86)\shttps_mg\http.exe service'. This misconfiguration allows a local attacker to place a malicious executable with the same name in a higher priority directory, causing the service to execute the malicious file instead of the legitimate one. Exploiting this flaw could allow arbitrary code execution, unauthorized access to the system, or service disruption. To mitigate the risk, the service path must be properly quoted, and systems must be kept up to date with security patches, while restricting physical and network access.
Severity CVSS v4.0: HIGH
Last modification:
26/03/2026

CVE-2025-55265

Publication date:
26/03/2026
HCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue to read sensitive files present in the system and may use it to craft further attacks.
Severity CVSS v4.0: Pending analysis
Last modification:
26/03/2026

CVE-2025-55266

Publication date:
26/03/2026
HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carry out unauthorized transaction behalf of the user.
Severity CVSS v4.0: Pending analysis
Last modification:
26/03/2026

CVE-2025-55267

Publication date:
26/03/2026
HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full control over the server.
Severity CVSS v4.0: Pending analysis
Last modification:
26/03/2026