Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-30200

Publication date:
05/09/2025
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which can be easily derived.
Severity CVSS v4.0: LOW
Last modification:
23/09/2025

CVE-2025-10014

Publication date:
05/09/2025
A flaw has been found in elunez eladmin up to 2.7. This impacts the function updateUserEmail of the file /api/users/updateEmail/ of the component Email Address Handler. Executing manipulation of the argument id/email can lead to improper authorization. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is said to be difficult. The exploit has been published and may be used. It is required to know the RSA-encrypted password of the attacked user account.
Severity CVSS v4.0: LOW
Last modification:
31/10/2025

CVE-2025-9998

Publication date:
05/09/2025
The sequence of packets received by a Networking server are not correctly checked.<br /> <br /> An attacker could exploit this vulnerability to send specially crafted messages to force the application to stop.
Severity CVSS v4.0: MEDIUM
Last modification:
05/09/2025

CVE-2025-9999

Publication date:
05/09/2025
Some payload elements of the messages sent between two stations in a networking architecture are not properly checked on the receiving station allowing an attacker to execute unauthorized commands in the application.
Severity CVSS v4.0: HIGH
Last modification:
05/09/2025

CVE-2025-58440

Publication date:
05/09/2025
Rejected reason: The unisharp/laravel-filemanager is a separate project, unrelated to laravel-filemanager.
Severity CVSS v4.0: Pending analysis
Last modification:
05/09/2025

CVE-2025-58214

Publication date:
05/09/2025
Improper Control of Filename for Include/Require Statement in PHP Program (&amp;#39;PHP Remote File Inclusion&amp;#39;) vulnerability in gavias Indutri allows PHP Local File Inclusion. This issue affects Indutri: from n/a through n/a.
Severity CVSS v4.0: Pending analysis
Last modification:
05/09/2025

CVE-2025-58628

Publication date:
05/09/2025
Improper Neutralization of Special Elements used in an SQL Command (&amp;#39;SQL Injection&amp;#39;) vulnerability in kamleshyadav Miraculous allows Blind SQL Injection. This issue affects Miraculous: from n/a through n/a.
Severity CVSS v4.0: Pending analysis
Last modification:
05/09/2025

CVE-2025-53307

Publication date:
05/09/2025
Improper Neutralization of Input During Web Page Generation (&amp;#39;Cross-site Scripting&amp;#39;) vulnerability in Brent Jett Assistant allows Reflected XSS. This issue affects Assistant: from n/a through 1.5.2.
Severity CVSS v4.0: Pending analysis
Last modification:
05/09/2025

CVE-2025-53571

Publication date:
05/09/2025
Missing Authorization vulnerability in VillaTheme HAPPY allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects HAPPY: from n/a through 1.0.6.
Severity CVSS v4.0: Pending analysis
Last modification:
05/09/2025

CVE-2025-54744

Publication date:
05/09/2025
Missing Authorization vulnerability in Stylemix MasterStudy LMS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MasterStudy LMS: from n/a through 3.6.15.
Severity CVSS v4.0: Pending analysis
Last modification:
05/09/2025

CVE-2025-57889

Publication date:
05/09/2025
Improper Control of Filename for Include/Require Statement in PHP Program (&amp;#39;PHP Remote File Inclusion&amp;#39;) vulnerability in RealMag777 InPost Gallery allows PHP Local File Inclusion. This issue affects InPost Gallery: from n/a through 2.1.4.5.
Severity CVSS v4.0: Pending analysis
Last modification:
05/09/2025

CVE-2025-58206

Publication date:
05/09/2025
Improper Control of Filename for Include/Require Statement in PHP Program (&amp;#39;PHP Remote File Inclusion&amp;#39;) vulnerability in ThemeMove MaxCoach allows PHP Local File Inclusion. This issue affects MaxCoach: from n/a through 3.2.5.
Severity CVSS v4.0: Pending analysis
Last modification:
28/01/2026