Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-2236

Publication date:
27/05/2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in OpenText Advanced Authentication allows Information Elicitation. The vulnerability could reveal sensitive information while managing and configuring of the external services.<br /> <br /> This issue affects Advanced Authentication versions before 6.5.
Severity CVSS v4.0: LOW
Last modification:
28/05/2025

CVE-2025-48797

Publication date:
27/05/2025
A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow.
Severity CVSS v4.0: Pending analysis
Last modification:
25/06/2025

CVE-2025-48798

Publication date:
27/05/2025
A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.
Severity CVSS v4.0: Pending analysis
Last modification:
25/06/2025

CVE-2025-48796

Publication date:
27/05/2025
A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a stack-based overflow. If a user opens.ANI files, GIMP may be used to store more information than the capacity allows. This flaw allows a malicious ANI file to trigger arbitrary code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
28/05/2025

CVE-2025-5272

Publication date:
27/05/2025
Memory safety bugs present in Firefox 138 and Thunderbird 138. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
11/06/2025

CVE-2025-5263

Publication date:
27/05/2025
Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
11/06/2025

CVE-2025-5264

Publication date:
27/05/2025
Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user&amp;#39;s system. This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
11/06/2025

CVE-2025-5265

Publication date:
27/05/2025
Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user&amp;#39;s system.<br /> *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
11/06/2025

CVE-2025-5266

Publication date:
27/05/2025
Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
11/06/2025

CVE-2025-5267

Publication date:
27/05/2025
A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
11/06/2025

CVE-2025-5269

Publication date:
27/05/2025
Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR
Severity CVSS v4.0: Pending analysis
Last modification:
11/06/2025

CVE-2025-5270

Publication date:
27/05/2025
In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability affects Firefox
Severity CVSS v4.0: Pending analysis
Last modification:
11/06/2025