Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-46222

Publication date:
23/04/2025
Rejected reason: Not used
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2025

CVE-2025-46223

Publication date:
23/04/2025
Rejected reason: Not used
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2025

CVE-2025-46224

Publication date:
23/04/2025
Rejected reason: Not used
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2025

CVE-2025-3441

Publication date:
22/04/2025
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Severity CVSS v4.0: Pending analysis
Last modification:
22/04/2025

CVE-2025-27087

Publication date:
22/04/2025
A vulnerability in the kernel of the Cray Operating System (COS) could allow an attacker to perform a local Denial of Service (DoS) attack.
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2025

CVE-2025-37088

Publication date:
22/04/2025
A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on race conditions and configuration, this vulnerability may lead to local/cluster unauthorized access.
Severity CVSS v4.0: Pending analysis
Last modification:
25/04/2025

CVE-2025-32965

Publication date:
22/04/2025
xrpl.js is a JavaScript/TypeScript API for interacting with the XRP Ledger in Node.js and the browser. Versions 4.2.1, 4.2.2, 4.2.3, and 4.2.4 of xrpl.js were compromised and contained malicious code designed to exfiltrate private keys. Version 2.14.2 is also malicious, though it is less likely to lead to exploitation as it is not compatible with other 2.x versions. Anyone who used one of these versions should stop immediately and rotate any private keys or secrets used with affected systems. Users of xrpl.js should pgrade to version 4.2.5 or 2.14.3 to receive a patch. To secure funds, think carefully about whether any keys may have been compromised by this supply chain attack, and mitigate by sending funds to secure wallets, and/or rotating keys. If any account's master key is potentially compromised, disable the key.
Severity CVSS v4.0: CRITICAL
Last modification:
23/04/2025

CVE-2025-37087

Publication date:
22/04/2025
A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the server host.
Severity CVSS v4.0: Pending analysis
Last modification:
01/05/2025

CVE-2025-26159

Publication date:
22/04/2025
Laravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of create or modify tags can inject malicious JavaScript code in the name field.
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2025

CVE-2025-29743

Publication date:
22/04/2025
D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.
Severity CVSS v4.0: Pending analysis
Last modification:
30/04/2025

CVE-2025-29621

Publication date:
22/04/2025
Francois Jacquet RosarioSIS v12.0.0 was discovered to contain a content spoofing vulnerability in the Theme configuration under the My Preferences module. This vulnerability allows attackers to manipulate application settings.
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2025

CVE-2025-31327

Publication date:
22/04/2025
SAP Field Logistics Manage Logistics application OData meta-data property is vulnerable to data tampering, due to which certain fields could be externally modified by an attacker causing low impact on integrity of the application. Confidentiality and availability are not impacted.
Severity CVSS v4.0: Pending analysis
Last modification:
23/04/2025