Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2025-50194

Publication date:
02/03/2026
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/cron/lang/check_parse_lang.php. This issue has been patched in version 1.11.30.
Severity CVSS v4.0: HIGH
Last modification:
02/03/2026

CVE-2025-50195

Publication date:
02/03/2026
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/manage.controller.php. This issue has been patched in version 1.11.30.
Severity CVSS v4.0: HIGH
Last modification:
02/03/2026

CVE-2025-50196

Publication date:
02/03/2026
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/editinstance.php via the POST main_database parameter. This issue has been patched in version 1.11.30.
Severity CVSS v4.0: HIGH
Last modification:
02/03/2026

CVE-2025-50197

Publication date:
02/03/2026
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/admin/sub_language_ajax.inc.php via the POST new_language parameter. This issue has been patched in version 1.11.30.
Severity CVSS v4.0: HIGH
Last modification:
02/03/2026

CVE-2025-50198

Publication date:
02/03/2026
Chamilo is a learning management system. Prior to version 1.11.30, Chamilo is vulnerable to deserialization of untrusted data in /plugin/vchamilo/views/import.php via POST configuration_file; POST course_path; POST home_path parameters. This issue has been patched in version 1.11.30.
Severity CVSS v4.0: HIGH
Last modification:
02/03/2026

CVE-2025-50193

Publication date:
02/03/2026
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS command Injection vulnerability in /plugin/vchamilo/views/import.php with the POST to_main_database parameter. This issue has been patched in version 1.11.30.
Severity CVSS v4.0: HIGH
Last modification:
02/03/2026

CVE-2026-26694

Publication date:
02/03/2026
code-projects Simple Student Alumni System v1.0 is vulnerale to SQL Injection in /TracerStudy/modal_view.php.
Severity CVSS v4.0: Pending analysis
Last modification:
02/03/2026

CVE-2026-26702

Publication date:
02/03/2026
sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/myitem_reuse.php.
Severity CVSS v4.0: Pending analysis
Last modification:
02/03/2026

CVE-2026-26703

Publication date:
02/03/2026
sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/advance_search.php.
Severity CVSS v4.0: Pending analysis
Last modification:
02/03/2026

CVE-2026-26695

Publication date:
02/03/2026
code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordstudent_edit.php.
Severity CVSS v4.0: Pending analysis
Last modification:
02/03/2026

CVE-2026-26696

Publication date:
02/03/2026
code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_edit.php.
Severity CVSS v4.0: Pending analysis
Last modification:
02/03/2026

CVE-2026-24107

Publication date:
02/03/2026
An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the value of `usbPartitionName`, which is directly used in `doSystemCmd`, may lead to critical command injection vulnerabilities.
Severity CVSS v4.0: Pending analysis
Last modification:
02/03/2026