Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-58260

Publication date:
02/10/2025
A vulnerability has been identified within Rancher Manager where a missing server-side validation on the `.username` field in Rancher can allow users with update permissions on other User resources to cause denial of access for targeted accounts.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2024-58267

Publication date:
02/10/2025
A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI tool is vulnerable to phishing attacks. The custom authentication protocol for SAML-based providers can be abused to steal Rancher’s authentication tokens.
Severity CVSS v4.0: Pending analysis
Last modification:
15/04/2026

CVE-2025-40992

Publication date:
02/10/2025
Stored XSS vulnerability in Creativeitem Sociopro due to lack of proper validation of user inputs via the endpoint '/sociopro/profile/update_profile', affecting to 'name' parameter via POST. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal his/her cookie session details.
Severity CVSS v4.0: MEDIUM
Last modification:
15/04/2026

CVE-2025-54293

Publication date:
02/10/2025
Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on the host system via crafted log file names or symbolic links.
Severity CVSS v4.0: HIGH
Last modification:
10/12/2025

CVE-2025-40990

Publication date:
02/10/2025
Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_bug/create/xxx", affecting to "title" and "description" parameters via POST. This vulnerability could allow a remote attacker to send a specially crafted query to an authenticated user and steal his/her cookie session details.
Severity CVSS v4.0: MEDIUM
Last modification:
08/10/2025

CVE-2025-40991

Publication date:
02/10/2025
Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_file/upload/xxxx", affecting to "description" parameter via POST. This vulnerability could allow a remote attacker to send a specially crafted query to an authenticated user and steal his/her cookie session details.
Severity CVSS v4.0: MEDIUM
Last modification:
08/10/2025

CVE-2025-40989

Publication date:
02/10/2025
Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_message/add/xxx", affecting to "message" parameter via POST. This vulnerability could allow a remote attacker to send a specially crafted query to an authenticated user and steal his/her cookie session details.
Severity CVSS v4.0: MEDIUM
Last modification:
08/10/2025

CVE-2025-61734

Publication date:
02/10/2025
Files or Directories Accessible to External Parties vulnerability in Apache Kylin.<br /> You are fine as long as the Kylin&amp;#39;s system and project admin access is well protected.<br /> <br /> This issue affects Apache Kylin: from 4.0.0 through 5.0.2.<br /> <br /> Users are recommended to upgrade to version 5.0.3, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
04/11/2025

CVE-2025-61735

Publication date:
02/10/2025
Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin.<br /> <br /> This issue affects Apache Kylin: from 4.0.0 through 5.0.2. You are fine as long as the Kylin&amp;#39;s system and project admin access is well protected.<br /> <br /> Users are recommended to upgrade to version 5.0.3, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
04/11/2025

CVE-2025-54289

Publication date:
02/10/2025
Privilege Escalation in operations API in Canonical LXD
Severity CVSS v4.0: HIGH
Last modification:
24/10/2025

CVE-2025-54290

Publication date:
02/10/2025
Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints.
Severity CVSS v4.0: MEDIUM
Last modification:
24/10/2025

CVE-2025-54291

Publication date:
02/10/2025
Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing HTTP status code responses.
Severity CVSS v4.0: MEDIUM
Last modification:
24/10/2025