Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-14714

Publication date:
15/12/2025
An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle<br /> <br /> <br /> <br /> <br /> By executing the bundled interpreter directly the attacker&amp;#39;s scripts run with the application&amp;#39;s TCC privileges<br /> <br /> <br /> <br /> <br /> In fixed versions parent-constraints are used to allow only the main application to launch interpreter with those permissions<br /> <br /> This issue affects LibreOffice on macOS: from 25.2 before
Severity CVSS v4.0: LOW
Last modification:
15/12/2025

CVE-2025-37732

Publication date:
15/12/2025
Improper neutralization of input during web page generation (&amp;#39;Cross-site Scripting&amp;#39;) (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the integration package upload functionality. This issue is related to ESA-2025-17 (CVE-2025-25018) bypassing that fix to achieve HTML injection.
Severity CVSS v4.0: Pending analysis
Last modification:
18/12/2025

CVE-2025-37731

Publication date:
15/12/2025
Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.
Severity CVSS v4.0: Pending analysis
Last modification:
18/12/2025

CVE-2025-11670

Publication date:
15/12/2025
Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. <br /> This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.
Severity CVSS v4.0: Pending analysis
Last modification:
18/12/2025

CVE-2025-14710

Publication date:
15/12/2025
A vulnerability was detected in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This affects an unknown part of the file /controller/api/OrderList.php. The manipulation of the argument telephone results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
Severity CVSS v4.0: MEDIUM
Last modification:
15/12/2025

CVE-2025-14711

Publication date:
15/12/2025
A flaw has been found in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This vulnerability affects unknown code of the file /controller/api/hotelList.php. This manipulation of the argument pickedHotelName/type causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continuous delivery The vendor was contacted early about this disclosure but did not respond in any way.
Severity CVSS v4.0: MEDIUM
Last modification:
15/12/2025

CVE-2025-14709

Publication date:
15/12/2025
A security vulnerability has been detected in Shiguangwu sgwbox N3 2.0.25. Affected by this issue is some unknown functionality of the file /usr/sbin/http_eshell_server of the component WIRELESSCFGGET Interface. The manipulation of the argument params leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity CVSS v4.0: HIGH
Last modification:
30/12/2025

CVE-2025-14023

Publication date:
15/12/2025
LINE client for iOS prior to 15.19 allows UI spoofing due to inconsistencies between the navigation state and the in-app browser&amp;#39;s user interface, which could create confusion about the trust context of displayed pages or interactive elements under specific conditions.
Severity CVSS v4.0: Pending analysis
Last modification:
07/01/2026

CVE-2025-14708

Publication date:
15/12/2025
A weakness has been identified in Shiguangwu sgwbox N3 2.0.25. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/http_eshell_server of the component WIREDCFGGET Interface. Executing manipulation of the argument params can lead to buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
Severity CVSS v4.0: HIGH
Last modification:
09/01/2026

CVE-2025-14022

Publication date:
15/12/2025
LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The SDK interfered with the application&amp;#39;s network processing, causing server certificate verification to be disabled for a significant portion of network traffic, which could allow a network-adjacent attacker to intercept or modify encrypted communications.
Severity CVSS v4.0: Pending analysis
Last modification:
07/01/2026

CVE-2025-14021

Publication date:
15/12/2025
The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious JavaScript within iframes while displaying trusted URLs, enabling phishing attacks through overlaid malicious content.
Severity CVSS v4.0: Pending analysis
Last modification:
18/12/2025

CVE-2025-14020

Publication date:
15/12/2025
LINE client for Android versions prior to 14.20 contains a UI spoofing vulnerability in the in-app browser where the full-screen security Toast notification is not properly re-displayed when users return from another application, potentially allowing attackers to conduct phishing attacks by impersonating legitimate interfaces.
Severity CVSS v4.0: Pending analysis
Last modification:
18/12/2025