Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-22142

Publication date:
13/01/2025
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In affected versions an admin can add the ability to have users fill out an additional field and users can inject javascript code into it that would be activated once a staffer visits the user's profile on staff panel. As a result an attacker can execute javascript code on the staffer's computer. This issue has been addressed in version 2.1.3 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Severity CVSS v4.0: MEDIUM
Last modification:
13/05/2025

CVE-2025-22144

Publication date:
13/01/2025
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or admincp.users.edit permissions can validate users and an attacker can reset their password. When the account is successfully approved by email the reset code is NULL, but when the account is manually validated by a user with admincp.core.emails or admincp.users.edit permissions then the reset_code will no longer be NULL but empty. An attacker can request http://localhost/nameless/index.php?route=/forgot_password/&c= and reset the password. As a result an attacker may compromise another users password and take over their account. This issue has been addressed in release version 2.1.3 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Severity CVSS v4.0: CRITICAL
Last modification:
13/05/2025

CVE-2024-46480

Publication date:
13/01/2025
An NTLM hash leak in Venki Supravizio BPM up to 18.0.1 allows authenticated attackers with Application Administrator access to escalate privileges on the underlying host system.
Severity CVSS v4.0: Pending analysis
Last modification:
13/01/2025

CVE-2024-46481

Publication date:
13/01/2025
The login page of Venki Supravizio BPM up to 18.1.1 is vulnerable to open redirect leading to reflected XSS.
Severity CVSS v4.0: Pending analysis
Last modification:
13/01/2025

CVE-2024-44771

Publication date:
13/01/2025
BigId PrivacyPortal v179 is vulnerable to Cross Site Scripting (XSS) via the "Label" field in the Report template function.
Severity CVSS v4.0: Pending analysis
Last modification:
14/01/2025

CVE-2024-46310

Publication date:
13/01/2025
Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via exposed API endpoint
Severity CVSS v4.0: Pending analysis
Last modification:
16/01/2025

CVE-2024-46921

Publication date:
13/01/2025
An issue was discovered in Samsung Mobile Processor and Modem Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W1000, Modem 5123, Modem 5300, Modem 5400. UE does not limit the number of attempts for the RRC Setup procedure in the 5G SA, leading to a denial of service (battery-drain attack).
Severity CVSS v4.0: Pending analysis
Last modification:
20/06/2025

CVE-2024-5743

Publication date:
13/01/2025
An attacker could exploit the &amp;#39;Use of Password Hash With Insufficient Computational Effort&amp;#39; vulnerability in EveHome Eve Play to execute arbitrary code.<br /> <br /> This issue affects Eve Play: through 1.1.42.
Severity CVSS v4.0: Pending analysis
Last modification:
13/01/2025

CVE-2024-46479

Publication date:
13/01/2025
Venki Supravizio BPM through 18.0.1 was discovered to contain an arbitrary file upload vulnerability. An authenticated attacker may upload a malicious file, leading to remote code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
13/01/2025

CVE-2024-46920

Publication date:
13/01/2025
An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a length check leads to a stack out-of-bounds write at loadInputBuffers.
Severity CVSS v4.0: Pending analysis
Last modification:
20/06/2025

CVE-2024-54999

Publication date:
13/01/2025
MonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General Information module.
Severity CVSS v4.0: Pending analysis
Last modification:
13/01/2025

CVE-2024-6352

Publication date:
13/01/2025
A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNet stack and lead to an assert
Severity CVSS v4.0: Pending analysis
Last modification:
13/01/2025