Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-45566

Publication date:
06/05/2025
Memory corruption during concurrent buffer access due to modification of the reference count.
Severity CVSS v4.0: Pending analysis
Last modification:
09/05/2025

CVE-2024-45554

Publication date:
06/05/2025
Memory corruption during concurrent SSR execution due to race condition on the global maps list.
Severity CVSS v4.0: Pending analysis
Last modification:
09/05/2025

CVE-2025-4340

Publication date:
06/05/2025
A vulnerability classified as critical has been found in D-Link DIR-890L and DIR-806A1 up to 100CNb11/108B03. Affected is the function sub_175C8 of the file /htdocs/soap.cgi. The manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Severity CVSS v4.0: MEDIUM
Last modification:
13/05/2025

CVE-2025-4333

Publication date:
06/05/2025
A vulnerability was found in feng_ha_ha/megagao ssm-erp and production_ssm up to 0.0.1. It has been classified as critical. This affects the function uploadFile of the file src/main/java/com/megagao/production/ssm/service/impl/FileServiceImpl.java. The manipulation of the argument uploadFile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is distributed under two entirely different names.
Severity CVSS v4.0: MEDIUM
Last modification:
15/04/2026

CVE-2025-46588

Publication date:
06/05/2025
Vulnerability of unauthorized access in the app lock module<br /> Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
Severity CVSS v4.0: Pending analysis
Last modification:
26/09/2025

CVE-2025-46589

Publication date:
06/05/2025
Vulnerability of unauthorized access in the app lock module<br /> Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
Severity CVSS v4.0: Pending analysis
Last modification:
26/09/2025

CVE-2025-46590

Publication date:
06/05/2025
Bypass vulnerability in the network search instruction authentication module<br /> Impact: Successful exploitation of this vulnerability can bypass authentication and enable access to some network search functions.
Severity CVSS v4.0: Pending analysis
Last modification:
09/05/2025

CVE-2025-46591

Publication date:
06/05/2025
Out-of-bounds data read vulnerability in the authorization module<br /> Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Severity CVSS v4.0: Pending analysis
Last modification:
26/09/2025

CVE-2025-46592

Publication date:
06/05/2025
Null pointer dereference vulnerability in the USB HDI driver module<br /> Impact: Successful exploitation of this vulnerability may affect availability.
Severity CVSS v4.0: Pending analysis
Last modification:
09/05/2025

CVE-2025-46593

Publication date:
06/05/2025
Process residence vulnerability in abnormal scenarios in the print module<br /> Impact: Successful exploitation of this vulnerability may affect availability.
Severity CVSS v4.0: Pending analysis
Last modification:
26/09/2025

CVE-2025-4331

Publication date:
06/05/2025
A vulnerability classified as critical was found in SourceCodester Online Student Clearance System 1.0. This vulnerability affects unknown code of the file /Admin/login.php. The manipulation of the argument id/username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity CVSS v4.0: MEDIUM
Last modification:
27/09/2025

CVE-2025-4332

Publication date:
06/05/2025
A vulnerability was found in PHPGurukul Company Visitor Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /visitor-detail.php. The manipulation of the argument editid/remark leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity CVSS v4.0: MEDIUM
Last modification:
30/09/2025