Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-21491

Publication date:
21/01/2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2025

CVE-2024-57540

Publication date:
21/01/2025
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (action) is copied to the stack without length verification.
Severity CVSS v4.0: Pending analysis
Last modification:
22/04/2025

CVE-2024-57541

Publication date:
21/01/2025
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (ipv6_protect_status) is copied to the stack without length verification.
Severity CVSS v4.0: Pending analysis
Last modification:
22/04/2025

CVE-2024-57542

Publication date:
21/01/2025
Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via the field id_email_check_btn.
Severity CVSS v4.0: Pending analysis
Last modification:
22/04/2025

CVE-2024-57543

Publication date:
21/01/2025
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (dhcpstart_ip) is copied to the stack without length verification.
Severity CVSS v4.0: Pending analysis
Last modification:
22/04/2025

CVE-2024-57544

Publication date:
21/01/2025
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (lan_ipaddr) is copied to the stack without length verification.
Severity CVSS v4.0: Pending analysis
Last modification:
22/04/2025

CVE-2024-57545

Publication date:
21/01/2025
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (hidden_dhcp_num) is copied to the stack without length verification.
Severity CVSS v4.0: Pending analysis
Last modification:
22/04/2025

CVE-2024-55958

Publication date:
21/01/2025
Northern.tech CFEngine Enterprise Mission Portal 3.24.0, 3.21.5, and below allows XSS. The fixed versions are 3.24.1 and 3.21.6.
Severity CVSS v4.0: Pending analysis
Last modification:
22/01/2025

CVE-2024-55959

Publication date:
21/01/2025
Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions.
Severity CVSS v4.0: Pending analysis
Last modification:
18/03/2025

CVE-2024-57360

Publication date:
21/01/2025
https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.
Severity CVSS v4.0: Pending analysis
Last modification:
18/03/2025

CVE-2024-57536

Publication date:
21/01/2025
Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via wizard_status.
Severity CVSS v4.0: Pending analysis
Last modification:
22/04/2025

CVE-2024-57537

Publication date:
21/01/2025
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (page) is copied to the stack without length verification.
Severity CVSS v4.0: Pending analysis
Last modification:
22/04/2025