Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-33659

Publication date:
11/02/2025
AMI APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation by a local attacker. Successful exploitation of these vulnerabilities may lead to overwriting arbitrary memory and execute arbitrary code at SMM level, also impacting Confidentiality, Integrity, and Availability.
Severity CVSS v4.0: MEDIUM
Last modification:
02/10/2025

CVE-2025-26492

Publication date:
11/02/2025
In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources
Severity CVSS v4.0: Pending analysis
Last modification:
16/05/2025

CVE-2025-26493

Publication date:
11/02/2025
In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab
Severity CVSS v4.0: Pending analysis
Last modification:
16/05/2025

CVE-2025-1231

Publication date:
11/02/2025
Improper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reuse the oracle user password after check-in due to crash in the password reset functionality.
Severity CVSS v4.0: Pending analysis
Last modification:
28/03/2025

CVE-2024-12366

Publication date:
11/02/2025
PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) instead of the intended explanation of the natural language processing by the LLM.
Severity CVSS v4.0: Pending analysis
Last modification:
11/02/2025

CVE-2025-0588

Publication date:
11/02/2025
In affected versions of Octopus Server it was possible for a user with sufficient access to set custom headers in all server responses. By submitting a specifically crafted referrer header the user could ensure that all subsequent server responses would return 500 errors rendering the site mostly unusable. The user would be able to subsequently set and unset the referrer header to control the denial of service state with a valid CSRF token whilst new CSRF tokens could not be generated.
Severity CVSS v4.0: MEDIUM
Last modification:
02/07/2025

CVE-2025-24812

Publication date:
11/02/2025
A vulnerability has been identified in SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0) (All versions
Severity CVSS v4.0: HIGH
Last modification:
11/02/2025

CVE-2025-24956

Publication date:
11/02/2025
A vulnerability has been identified in OpenV2G (All versions
Severity CVSS v4.0: MEDIUM
Last modification:
24/09/2025

CVE-2025-26490

Publication date:
11/02/2025
Rejected reason: This CVE ID is a duplicate of CVE-2025-26495.
Severity CVSS v4.0: Pending analysis
Last modification:
14/02/2025

CVE-2025-26491

Publication date:
11/02/2025
Rejected reason: This CVE ID is a duplicate of CVE-2025-26494.
Severity CVSS v4.0: Pending analysis
Last modification:
14/02/2025

CVE-2025-0862

Publication date:
11/02/2025
The SuperSaaS – online appointment scheduling plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘after’ parameter in all versions up to, and including, 2.1.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is limited to Chromium-based browsers (e.g. Chrome, Edge, Brave).
Severity CVSS v4.0: Pending analysis
Last modification:
11/02/2025

CVE-2025-23363

Publication date:
11/02/2025
A vulnerability has been identified in Teamcenter V14.1 (All versions), Teamcenter V14.2 (All versions), Teamcenter V14.3 (All versions
Severity CVSS v4.0: MEDIUM
Last modification:
24/09/2025