Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-63710

Publication date:
10/11/2025
The send_message.php endpoint in SourceCodester Simple Public Chat Room 1.0 is vulnerable to Cross-Site Request Forgery (CSRF). The application does not implement any CSRF-protection mechanisms such as tokens, nonces, or same-site cookie restrictions. An attacker can create a malicious HTML page that, when visited by an authenticated user, will automatically submit a forged POST request to the vulnerable endpoint. This request will be executed with the victim's privileges, allowing the attacker to perform unauthorized actions on their behalf, such as sending arbitrary messages in any chat room.
Severity CVSS v4.0: Pending analysis
Last modification:
17/11/2025

CVE-2025-63709

Publication date:
10/11/2025
A Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Simple To-Do List System 1.0 in the "Add Tasks" text input. An authenticated user can submit HTML/JavaScript that is not correctly sanitized or encoded on output. The injected script is stored and later rendered in the browser of any user who views the task, allowing execution of arbitrary script in the context of the victim's browser.
Severity CVSS v4.0: Pending analysis
Last modification:
01/12/2025

CVE-2025-12480

Publication date:
10/11/2025
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.
Severity CVSS v4.0: Pending analysis
Last modification:
14/11/2025

CVE-2025-64685

Publication date:
10/11/2025
In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2025

CVE-2025-64686

Publication date:
10/11/2025
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it was fixed before public disclosure and did not affect any released versions.
Severity CVSS v4.0: Pending analysis
Last modification:
02/12/2025

CVE-2025-64687

Publication date:
10/11/2025
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it was fixed before public disclosure and did not affect any released versions.
Severity CVSS v4.0: Pending analysis
Last modification:
02/12/2025

CVE-2025-64688

Publication date:
10/11/2025
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it relates to internal functionality that is not available to customers.
Severity CVSS v4.0: Pending analysis
Last modification:
02/12/2025

CVE-2025-64689

Publication date:
10/11/2025
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it relates to internal functionality that is not available to customers.
Severity CVSS v4.0: Pending analysis
Last modification:
02/12/2025

CVE-2025-64690

Publication date:
10/11/2025
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it relates to internal functionality that is not available to customers.
Severity CVSS v4.0: Pending analysis
Last modification:
02/12/2025

CVE-2025-64457

Publication date:
10/11/2025
In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition
Severity CVSS v4.0: Pending analysis
Last modification:
12/01/2026

CVE-2025-64456

Publication date:
10/11/2025
In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation
Severity CVSS v4.0: Pending analysis
Last modification:
20/11/2025

CVE-2025-64681

Publication date:
10/11/2025
In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations
Severity CVSS v4.0: Pending analysis
Last modification:
20/11/2025