Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-25329

Publication date:
27/02/2025
An issue in Tencent Technology (Beijing) Company Limited Tencent MicroVision iOS 8.137.0 allows attackers to access sensitive user information via supplying a crafted link.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2024-9285

Publication date:
27/02/2025
A vulnerability was found in Tu Yafeng Via Browser up to 5.9.0 on Android. It has been rated as problematic. This issue affects some unknown processing of the component Javascript Bridge. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
Severity CVSS v4.0: MEDIUM
Last modification:
15/04/2026

CVE-2025-25330

Publication date:
27/02/2025
An issue in Boohee Technology Boohee Health iOS 13.0.13 allows attackers to access sensitive user information via supplying a crafted link.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2025-25331

Publication date:
27/02/2025
An issue in Beitatong Technology LianJia iOS 9.83.50 allows attackers to access sensitive user information via supplying a crafted link.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2025-25333

Publication date:
27/02/2025
An issue in IKEA CN iOS 4.13.0 allows attackers to access sensitive user information via supplying a crafted link.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2025-25334

Publication date:
27/02/2025
An issue in Suning Commerce Group Suning EMall iOS 9.5.198 allows attackers to access sensitive user information via supplying a crafted link.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2025-1755

Publication date:
27/02/2025
MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1
Severity CVSS v4.0: Pending analysis
Last modification:
09/04/2025

CVE-2025-1756

Publication date:
27/02/2025
mongosh may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privilege, when a crafted file is stored in C:\node_modules\. This issue affects mongosh prior to 2.3.0
Severity CVSS v4.0: Pending analysis
Last modification:
09/04/2025

CVE-2025-25323

Publication date:
27/02/2025
An issue in Qianjin Network Information Technology (Shanghai) Co., Ltd 51Job iOS 14.22.0 allows attackers to access sensitive user information via supplying a crafted link.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2025-25324

Publication date:
27/02/2025
An issue in Shandong Provincial Big Data Center AiShanDong iOS 5.0.0 allows attackers to access sensitive user information via supplying a crafted link.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2025-25325

Publication date:
27/02/2025
An issue in Yibin Fengguan Network Technology Co., Ltd YuPao DirectHire iOS 8.8.0 allows attackers to access sensitive user information via supplying a crafted link.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2025-25326

Publication date:
27/02/2025
An issue in Merchants Union Consumer Finance Company Limited Merchants Union Finance iOS 6.19.0 allows attackers to access sensitive user information via supplying a crafted link.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026