Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-25770

Publication date:
21/02/2025
Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /agency/AgencyUserController.java.
Severity CVSS v4.0: Pending analysis
Last modification:
28/03/2025

CVE-2025-25604

Publication date:
21/02/2025
Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua.
Severity CVSS v4.0: Pending analysis
Last modification:
04/04/2025

CVE-2025-25605

Publication date:
21/02/2025
Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua.
Severity CVSS v4.0: Pending analysis
Last modification:
04/04/2025

CVE-2025-25772

Publication date:
21/02/2025
A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers to arbitrarily add Administrator accounts via a crafted request.
Severity CVSS v4.0: Pending analysis
Last modification:
09/07/2025

CVE-2020-19248

Publication date:
21/02/2025
SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to contaminate template content by searching for page contamination URLs, thus triggering vulnerabilities when the program uses eval statements to parse templates.
Severity CVSS v4.0: Pending analysis
Last modification:
07/04/2025

CVE-2025-25876

Publication date:
21/02/2025
A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /delete.php. The attack can use SQL injection to obtain sensitive data.
Severity CVSS v4.0: Pending analysis
Last modification:
28/03/2025

CVE-2025-25877

Publication date:
21/02/2025
A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /admin.php. The attack can use SQL injection to obtain sensitive data.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2025

CVE-2025-25878

Publication date:
21/02/2025
A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /del.php. The attack can use SQL injection to obtain sensitive data.
Severity CVSS v4.0: Pending analysis
Last modification:
07/04/2025

CVE-2025-25765

Publication date:
21/02/2025
MRCMS v3.1.2 was discovered to contain an arbitrary file write vulnerability via the component /file/save.do.
Severity CVSS v4.0: Pending analysis
Last modification:
28/03/2025

CVE-2025-25766

Publication date:
21/02/2025
An arbitrary file upload vulnerability in the component /file/savefile.do of MRCMS v3.1.2 allows attackers to execute arbitrary code via uploading a crafted .jsp file.
Severity CVSS v4.0: Pending analysis
Last modification:
28/03/2025

CVE-2025-25875

Publication date:
21/02/2025
A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /message.php. The attack can use SQL injection to obtain sensitive data.
Severity CVSS v4.0: Pending analysis
Last modification:
28/03/2025

CVE-2024-55156

Publication date:
21/02/2025
An XML External Entity (XXE) vulnerability in the deserializeArgs() method of Java SDK for CloudEvents v4.0.1 allows attackers to access sensitive information via supplying a crafted XML-formatted event message.
Severity CVSS v4.0: Pending analysis
Last modification:
17/03/2025