Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-27604

Publication date:
07/03/2025
XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. The homepage of the application is public which enables a guest to download the package which might contain sensitive information. This vulnerability is fixed in 1.11.7.
Severity CVSS v4.0: Pending analysis
Last modification:
13/03/2025

CVE-2025-27607

Publication date:
07/03/2025
Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE through a missing dependency. This occurred because msgspec-python313-pre was deleted by the owner leaving the name open to being claimed by a third party. If the package was claimed, it would allow them RCE on any Python JSON Logger user who installed the development dependencies on Python 3.13 (e.g. pip install python-json-logger[dev]). This issue has been resolved with 3.3.0.
Severity CVSS v4.0: Pending analysis
Last modification:
01/07/2025

CVE-2025-0162

Publication date:
07/03/2025
IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Severity CVSS v4.0: Pending analysis
Last modification:
13/03/2025

CVE-2024-53694

Publication date:
07/03/2025
A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local attackers who have gained user access to gain access to otherwise unauthorized resources.<br /> <br /> We have already fixed the vulnerability in the following versions:<br /> QVPN Device Client for Mac 2.2.5 and later<br /> Qsync for Mac 5.1.3 and later<br /> Qfinder Pro Mac 7.11.1 and later
Severity CVSS v4.0: HIGH
Last modification:
07/03/2025

CVE-2024-53695

Publication date:
07/03/2025
A buffer overflow vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to modify memory or crash processes.<br /> <br /> We have already fixed the vulnerability in the following version:<br /> HBS 3 Hybrid Backup Sync 25.1.4.952 and later
Severity CVSS v4.0: MEDIUM
Last modification:
07/03/2025

CVE-2024-53696

Publication date:
07/03/2025
A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read application data.<br /> <br /> We have already fixed the vulnerability in the following versions:<br /> QuLog Center 1.7.0.829 ( 2024/10/01 ) and later<br /> QuLog Center 1.8.0.888 ( 2024/10/15 ) and later<br /> QTS 4.5.4.2957 build 20241119 and later<br /> QuTS hero h4.5.4.2956 build 20241119 and later
Severity CVSS v4.0: MEDIUM
Last modification:
07/03/2025

CVE-2024-53697

Publication date:
07/03/2025
An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory.<br /> <br /> We have already fixed the vulnerability in the following versions:<br /> QTS 5.2.3.3006 build 20250108 and later<br /> QuTS hero h5.2.3.3006 build 20250108 and later
Severity CVSS v4.0: LOW
Last modification:
07/03/2025

CVE-2024-53698

Publication date:
07/03/2025
A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify memory.<br /> <br /> We have already fixed the vulnerability in the following versions:<br /> QTS 5.2.3.3006 build 20250108 and later<br /> QuTS hero h5.2.3.3006 build 20250108 and later
Severity CVSS v4.0: LOW
Last modification:
07/03/2025

CVE-2024-53699

Publication date:
07/03/2025
An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory.<br /> <br /> We have already fixed the vulnerability in the following versions:<br /> QTS 5.2.3.3006 build 20250108 and later<br /> QuTS hero h5.2.3.3006 build 20250108 and later
Severity CVSS v4.0: LOW
Last modification:
07/03/2025

CVE-2024-53700

Publication date:
07/03/2025
A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands.<br /> <br /> We have already fixed the vulnerability in the following version:<br /> QuRouter 2.4.6.028 and later
Severity CVSS v4.0: MEDIUM
Last modification:
07/03/2025

CVE-2024-50390

Publication date:
07/03/2025
A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands.<br /> <br /> We have already fixed the vulnerability in the following version:<br /> QuRouter 2.4.5.032 and later
Severity CVSS v4.0: HIGH
Last modification:
07/03/2025

CVE-2024-50394

Publication date:
07/03/2025
An improper certificate validation vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow remote attackers to compromise the security of the system.<br /> <br /> We have already fixed the vulnerability in the following version:<br /> Helpdesk 3.3.3 and later
Severity CVSS v4.0: HIGH
Last modification:
07/03/2025