Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-31756

Publication date:
01/04/2025
Cross-Site Request Forgery (CSRF) vulnerability in tuyennv TZ PlusGallery allows Cross Site Request Forgery. This issue affects TZ PlusGallery: from n/a through 1.5.5.
Severity CVSS v4.0: Pending analysis
Last modification:
01/04/2025

CVE-2025-31757

Publication date:
01/04/2025
Missing Authorization vulnerability in BinaryCarpenter Free Woocommerce Product Table View allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Free Woocommerce Product Table View: from n/a through 1.78.
Severity CVSS v4.0: Pending analysis
Last modification:
01/04/2025

CVE-2025-31759

Publication date:
01/04/2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BooSpot Boo Recipes allows Stored XSS. This issue affects Boo Recipes: from n/a through 2.4.1.
Severity CVSS v4.0: Pending analysis
Last modification:
01/04/2025

CVE-2025-31760

Publication date:
01/04/2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snapwidget SnapWidget Social Photo Feed Widget allows DOM-Based XSS. This issue affects SnapWidget Social Photo Feed Widget: from n/a through 1.1.0.
Severity CVSS v4.0: Pending analysis
Last modification:
01/04/2025

CVE-2025-31761

Publication date:
01/04/2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DEJAN Hypotext allows Stored XSS. This issue affects Hypotext: from n/a through 1.0.1.
Severity CVSS v4.0: Pending analysis
Last modification:
01/04/2025

CVE-2025-31762

Publication date:
01/04/2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andreyazimov Sheet2Site allows Stored XSS. This issue affects Sheet2Site: from n/a through 1.0.18.
Severity CVSS v4.0: Pending analysis
Last modification:
01/04/2025

CVE-2025-31748

Publication date:
01/04/2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpopal Opal Portfolio allows Stored XSS. This issue affects Opal Portfolio: from n/a through 1.0.4.
Severity CVSS v4.0: Pending analysis
Last modification:
01/04/2025

CVE-2025-31749

Publication date:
01/04/2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPelite HMH Footer Builder For Elementor allows Stored XSS. This issue affects HMH Footer Builder For Elementor: from n/a through 1.0.
Severity CVSS v4.0: Pending analysis
Last modification:
01/04/2025

CVE-2025-31750

Publication date:
01/04/2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in doit Breaking News WP allows Stored XSS. This issue affects Breaking News WP: from n/a through 1.3.
Severity CVSS v4.0: Pending analysis
Last modification:
01/04/2025

CVE-2025-31751

Publication date:
01/04/2025
Cross-Site Request Forgery (CSRF) vulnerability in doit Breaking News WP allows Cross Site Request Forgery. This issue affects Breaking News WP: from n/a through 1.3.
Severity CVSS v4.0: Pending analysis
Last modification:
01/04/2025

CVE-2025-31752

Publication date:
01/04/2025
Missing Authorization vulnerability in termel Bulk Fields Editor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bulk Fields Editor: from n/a through 1.8.0.
Severity CVSS v4.0: Pending analysis
Last modification:
01/04/2025

CVE-2025-31754

Publication date:
01/04/2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DobsonDev DobsonDev Shortcodes allows Stored XSS. This issue affects DobsonDev Shortcodes: from n/a through 2.1.12.
Severity CVSS v4.0: Pending analysis
Last modification:
01/04/2025