Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-1424

Publication date:
04/03/2025
A privilege escalation vulnerability in PocketBook InkPad Color 3 allows attackers to escalate to root privileges if they gain physical access to the device.<br /> This issue affects InkPad Color 3 in version U743k3.6.8.3671.
Severity CVSS v4.0: HIGH
Last modification:
04/03/2025

CVE-2025-1425

Publication date:
04/03/2025
A Sudo privilege misconfiguration vulnerability in PocketBook InkPad Color 3 on Linux, ARM allows attackers to read file contents on the device.This issue affects InkPad Color 3: U743k3.6.8.3671.
Severity CVSS v4.0: MEDIUM
Last modification:
04/03/2025

CVE-2024-50707

Publication date:
04/03/2025
Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary code via the X-Forwarded-For header in an HTTP GET request.
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2025

CVE-2024-50704

Publication date:
04/03/2025
Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary code via a specially crafted HTTP POST request.
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2025

CVE-2024-11957

Publication date:
04/03/2025
Improper verification of the digital signature in ksojscore.dll in Kingsoft WPS Office in versions equal or less than 12.1.0.18276<br /> <br /> on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.2.0.16909 to mitigate CVE-2024-7262 was not restrictive enough.
Severity CVSS v4.0: CRITICAL
Last modification:
04/03/2025

CVE-2024-9149

Publication date:
04/03/2025
Improper Neutralization of Special Elements used in an SQL Command (&amp;#39;SQL Injection&amp;#39;) vulnerability in Wind Media E-Commerce Website Template allows SQL Injection.This issue affects E-Commerce Website Template: before v1.5.
Severity CVSS v4.0: Pending analysis
Last modification:
04/03/2025

CVE-2024-50705

Publication date:
04/03/2025
Unauthenticated reflected cross-site scripting (XSS) vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary scripts via the page parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
21/05/2025

CVE-2024-50706

Publication date:
04/03/2025
Unauthenticated SQL injection vulnerability in Uniguest Tripleplay version 23.1+ allows remote attackers to execute arbitrary SQL queries on the backend database.
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2025

CVE-2025-1941

Publication date:
04/03/2025
Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
28/03/2025

CVE-2025-1942

Publication date:
04/03/2025
When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
28/03/2025

CVE-2025-27424

Publication date:
04/03/2025
Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page This vulnerability affects Firefox for iOS
Severity CVSS v4.0: Pending analysis
Last modification:
28/03/2025

CVE-2025-27426

Publication date:
04/03/2025
Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL This vulnerability affects Firefox for iOS
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025