Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
459 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.52% | — | Cache Images Project Cache Images | 11/7/2022 | 17/6/2026 | The Cache Images WordPress plugin before 3.2.1 does not implement nonce checks, which could allow attackers to make any logged user upload images via a CSRF attack. | |
| Modificada | Alta (8.8) | 0.61% | — | HOT Linked Image Cacher Project HOT Linked Image Cacher | 13/6/2022 | 17/6/2026 | The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache images from external domains on the server, which could lead to legal risks (due to copyright violations or licensing rules). | |
| Modificada | Media (6.8) | 0.28% | — | Nvidia Omniverse CacheNvidia Omniverse Nucleus | 29/4/2022 | 17/6/2026 | NVIDIA Omniverse Nucleus and Cache contain a vulnerability in its configuration of OpenSSL, where an attacker with physical access to the system can cause arbitrary code execution which can impact confidentiality, integrity, and availability. | |
| Modificada | Alta (7.2) | 1.3% | — | Geoserver Geowebcache | 14/4/2022 | 17/6/2026 | GeoWebCache is a tile caching server implemented in Java. The GeoWebCache disk quota mechanism can perform an unchecked JNDI lookup, which in turn can be used to perform class deserialization and result in arbitrary code execution. While in GeoWebCache the JNDI strings are provided via local configuration file, in… | |
| Modificada | Crítica (9.8) | 21% | — | PHP Memcached | 5/4/2022 | 17/6/2026 | PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. Note: Third parties have disputed this as not affecting PHP-Memcached directly. | |
| Modificada | Media (5.3) | 0.76% | — | Mittwald Varnishcache | 19/2/2022 | 17/6/2026 | An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content element renderer component does not include an access check. This allows an unauthenticated user to render various content elements, resulting in insecure direct object reference (IDOR), with the… | |
| Modificada | Crítica (9.1) | 2.0% | — | Varnish-software Varnich CacheVarnish-software Varnish CacheVarnish-software Varnish Cache PlusVarnish Cache Project Varnish Cache+2 | 26/1/2022 | 17/6/2026 | In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections. | |
| Modificada | Crítica (9.8) | 1.9% | — | Cached-path-relative Project Cached-path-relativeDebian Linux | 21/1/2022 | 17/6/2026 | The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using… | |
| Modificada | Media (6.1) | 1.2% | — | Litespeedtech Litespeed Cache | 3/1/2022 | 17/6/2026 | The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from QUIC.cloud servers, allowing attackers to make requests to certain endpoints by using a specific X-Forwarded-For header value. In addition, one of the endpoint could be used to set CSS code if a setting is enabled,… | |
| Modificada | Media (4.8) | 0.65% | — | Litespeedtech Litespeed Cache | 3/1/2022 | 17/6/2026 | The LiteSpeed Cache WordPress plugin before 4.4.4 does not escape the qc_res parameter before outputting it back in the JS code of an admin page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Crítica (9.8) | 2.4% | — | Gradle Build Cache NodeGradle Enterprise | 27/10/2021 | 17/6/2026 | In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and remote code execution when running the build cache node with its default configuration. This configuration allows anonymous access to the configuration user interface and anonymous write access to… | |
| Modificada | Alta (7.5) | 2.9% | — | Squid-cache SquidFedoraproject Fedora | 18/10/2021 | 17/6/2026 | An issue was discovered in Squid 5.0.6 through 5.1.x before 5.2. When validating an origin server or peer certificate, Squid may incorrectly classify certain certificates as trusted. This problem allows a remote server to obtain security trust well improperly. This indication of trust may be passed along to clients,… | |
| Modificada | Media (6.5) | 8.2% | 💥 Exploit | Chachethq Cachet | 26/8/2021 | 17/6/2026 | Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in the `SearchableTrait#scopeSearch()`. Attackers without authentication can utilize this vulnerability to exfiltrate sensitive data from the database such as administrator's password and session. The… | |
| Modificada | Media (4.3) | 6.1% | 💥 Exploit | Phpfastcache | 12/8/2021 | 17/6/2026 | PhpFastCache is a high-performance backend cache system (packagist package phpfastcache/phpfastcache). In versions before 6.1.5, 7.1.2, and 8.0.7 the `phpinfo()` can be exposed if the `/vendor` is not protected from public access. This is a rare situation today since the vendor directory is often located outside the… | |
| Modificada | Alta (8.1) | 1.1% | — | Cache Project Cache | 8/8/2021 | 17/6/2026 | An issue was discovered in the cache crate through 2020-11-24 for Rust. There are unconditional implementations of Send and Sync for Cache<K>. | |
| Modificada | Media (6.1) | 1.9% | 💥 Exploit | Boldgrid W3 Total Cache | 19/7/2021 | 17/6/2026 | The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the 'Anonymously track usage to improve product quality' setting is enabled, as the parameter is output in a JavaScript context without proper… | |
| Modificada | Media (6.1) | 1.9% | 💥 Exploit | Boldgrid W3 Total Cache | 19/7/2021 | 17/6/2026 | The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability within the "extension" parameter in the Extensions dashboard, which is output in an attribute without being escaped first. This could allow an attacker, who can convince an authenticated… | |
| Modificada | Media (6.5) | 1.6% | — | Varnish-cache Varnish CacheVarnish-software Varnish CacheVarnish Cache Project Varnish CacheFedoraproject Fedora+1 | 14/7/2021 | 17/6/2026 | Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x before 6.6.1, and 6.0 LTS before 6.0.8. | |
| Modificada | Media (4.8) | 0.62% | — | Boldgrid W3 Total Cache | 12/7/2021 | 17/6/2026 | The W3 Total Cache WordPress plugin before 2.1.3 did not sanitise or escape some of its CDN settings, allowing high privilege users to use JavaScript in them, which will be output in the page, leading to an authenticated Stored Cross-Site Scripting issue | |
| Modificada | Media (6.5) | 16% | — | Squid-cache SquidFedoraproject FedoraNetapp Cloud Manager | 8/6/2021 | 17/6/2026 | An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent. | |
| Modificada | Media (5.4) | 4.5% | — | Automattic WP Super Cache | 1/6/2021 | 17/6/2026 | The WP Super Cache WordPress plugin before 1.7.3 did not properly sanitise its wp_cache_location parameter in its settings, which could lead to a Stored Cross-Site Scripting issue. | |
| Modificada | Alta (7.2) | 1.9% | — | Automattic WP Super Cache | 1/6/2021 | 17/6/2026 | The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of WP Super Cache WordPress plugin before 1.7.3 result in RCE because they allow input of '$' and '\n'. This is due to an incomplete fix of CVE-2021-24209. | |
| Modificada | Media (6.5) | 80% | — | Squid-cache SquidFedoraproject FedoraDebian Linux | 28/5/2021 | 17/6/2026 | Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTP response. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent by the server. | |
| Modificada | Media (6.5) | 5.3% | — | Squid-cache SquidDebian LinuxNetapp Cloud ManagerFedoraproject Fedora | 27/5/2021 | 17/6/2026 | An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to an input-validation bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy). A client sends an HTTP Range request to trigger this. | |
| Modificada | Media (6.5) | 96% | — | Squid-cache SquidDebian LinuxFedoraproject FedoraNetapp Cloud Manager | 27/5/2021 | 17/6/2026 | An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy) via HTTP Range request processing. |