Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2024-25262

Publication date:
29/02/2024
texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted TTF file.
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2025

CVE-2024-25006

Publication date:
29/02/2024
XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.
Severity CVSS v4.0: Pending analysis
Last modification:
08/05/2025

CVE-2024-25065

Publication date:
29/02/2024
Possible path traversal in Apache OFBiz allowing authentication bypass.<br /> Users are recommended to upgrade to version 18.12.12, that fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
05/05/2025

CVE-2024-25128

Publication date:
29/02/2024
Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, it allows an attacker to forge an HTTP request, that could deceive the backend into using any requested OpenID service. This vulnerability could grant an attacker unauthorised privilege access if a custom OpenID service is deployed by the attacker and accessible by the backend. This vulnerability is only exploitable when the application is using the OpenID 2.0 authorization protocol. Upgrade to Flask-AppBuilder 4.3.11 to fix the vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
14/10/2025

CVE-2024-24701

Publication date:
29/02/2024
Cross-Site Request Forgery (CSRF) vulnerability in Native Grid LLC A no-code page builder for beautiful performance-based content.This issue affects A no-code page builder for beautiful performance-based content: from n/a through 2.1.20.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
08/01/2025

CVE-2024-24708

Publication date:
29/02/2024
Cross-Site Request Forgery (CSRF) vulnerability in W3speedster W3SPEEDSTER.This issue affects W3SPEEDSTER: from n/a through 7.19.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
07/05/2025

CVE-2024-23946

Publication date:
29/02/2024
Possible path traversal in Apache OFBiz allowing file inclusion.<br /> Users are recommended to upgrade to version 18.12.12, that fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
13/08/2024

CVE-2024-24146

Publication date:
29/02/2024
A memory leak issue discovered in parseSWF_DEFINEBUTTON in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.
Severity CVSS v4.0: Pending analysis
Last modification:
27/03/2025

CVE-2024-24147

Publication date:
29/02/2024
A memory leak issue discovered in parseSWF_FILLSTYLEARRAY in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.
Severity CVSS v4.0: Pending analysis
Last modification:
29/08/2024

CVE-2024-24149

Publication date:
29/02/2024
A memory leak issue discovered in parseSWF_GLYPHENTRY in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.
Severity CVSS v4.0: Pending analysis
Last modification:
13/08/2024

CVE-2024-24150

Publication date:
29/02/2024
A memory leak issue discovered in parseSWF_TEXTRECORD in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.
Severity CVSS v4.0: Pending analysis
Last modification:
27/03/2025

CVE-2024-24155

Publication date:
29/02/2024
Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot correctly delete when we got an no audio track found error. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mp4 file.
Severity CVSS v4.0: Pending analysis
Last modification:
16/01/2025