Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-44172

Publication date:
02/06/2025
Tenda AC6 V15.03.05.16 was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement function.
Severity CVSS v4.0: Pending analysis
Last modification:
03/06/2025

CVE-2025-37095

Publication date:
02/06/2025
A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.
Severity CVSS v4.0: MEDIUM
Last modification:
02/07/2025

CVE-2025-20001

Publication date:
02/06/2025
An out-of-bounds read vulnerability exists in High-Logic FontCreator 15.0.0.3015. A specially crafted font file can trigger this vulnerability which can lead to disclosure of sensitive information. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
26/08/2025

CVE-2024-48877

Publication date:
02/06/2025
A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility version 0.95. A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2025

CVE-2024-52035

Publication date:
02/06/2025
An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2025

CVE-2024-54028

Publication date:
02/06/2025
An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2025

CVE-2025-5447

Publication date:
02/06/2025
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been declared as critical. This vulnerability affects the function ssid1MACFilter of the file /goform/ssid1MACFilter. The manipulation of the argument apselect_%d/newap_text_%d leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity CVSS v4.0: MEDIUM
Last modification:
02/07/2025

CVE-2025-37091

Publication date:
02/06/2025
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
Severity CVSS v4.0: Pending analysis
Last modification:
02/07/2025

CVE-2025-37090

Publication date:
02/06/2025
A server-side request forgery vulnerability exists in HPE StoreOnce Software.
Severity CVSS v4.0: MEDIUM
Last modification:
02/07/2025

CVE-2025-37092

Publication date:
02/06/2025
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
Severity CVSS v4.0: HIGH
Last modification:
02/07/2025

CVE-2025-37093

Publication date:
02/06/2025
An authentication bypass vulnerability exists in HPE StoreOnce Software.
Severity CVSS v4.0: Pending analysis
Last modification:
02/07/2025

CVE-2025-37094

Publication date:
02/06/2025
A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software.
Severity CVSS v4.0: Pending analysis
Last modification:
02/07/2025