Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

459 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.52%—Cache Images Project Cache Images11/7/202217/6/2026
The Cache Images WordPress plugin before 3.2.1 does not implement nonce checks, which could allow attackers to make any logged user upload images via a CSRF attack.
ModificadaAlta (8.8)0.61%—HOT Linked Image Cacher Project HOT Linked Image Cacher13/6/202217/6/2026
The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache images from external domains on the server, which could lead to legal risks (due to copyright violations or licensing rules).
ModificadaMedia (6.8)0.28%—Nvidia Omniverse CacheNvidia Omniverse Nucleus29/4/202217/6/2026
NVIDIA Omniverse Nucleus and Cache contain a vulnerability in its configuration of OpenSSL, where an attacker with physical access to the system can cause arbitrary code execution which can impact confidentiality, integrity, and availability.
ModificadaAlta (7.2)1.3%—Geoserver Geowebcache14/4/202217/6/2026
GeoWebCache is a tile caching server implemented in Java. The GeoWebCache disk quota mechanism can perform an unchecked JNDI lookup, which in turn can be used to perform class deserialization and result in arbitrary code execution. While in GeoWebCache the JNDI strings are provided via local configuration file, in…
ModificadaCrítica (9.8)21%—PHP Memcached5/4/202217/6/2026
PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. Note: Third parties have disputed this as not affecting PHP-Memcached directly.
ModificadaMedia (5.3)0.76%—Mittwald Varnishcache19/2/202217/6/2026
An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content element renderer component does not include an access check. This allows an unauthenticated user to render various content elements, resulting in insecure direct object reference (IDOR), with the…
ModificadaCrítica (9.1)2.0%—Varnish-software Varnich CacheVarnish-software Varnish CacheVarnish-software Varnish Cache PlusVarnish Cache Project Varnish Cache+226/1/202217/6/2026
In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.
ModificadaCrítica (9.8)1.9%—Cached-path-relative Project Cached-path-relativeDebian Linux21/1/202217/6/2026
The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using…
ModificadaMedia (6.1)1.2%—Litespeedtech Litespeed Cache3/1/202217/6/2026
The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from QUIC.cloud servers, allowing attackers to make requests to certain endpoints by using a specific X-Forwarded-For header value. In addition, one of the endpoint could be used to set CSS code if a setting is enabled,…
ModificadaMedia (4.8)0.65%—Litespeedtech Litespeed Cache3/1/202217/6/2026
The LiteSpeed Cache WordPress plugin before 4.4.4 does not escape the qc_res parameter before outputting it back in the JS code of an admin page, leading to a Reflected Cross-Site Scripting
ModificadaCrítica (9.8)2.4%—Gradle Build Cache NodeGradle Enterprise27/10/202117/6/2026
In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and remote code execution when running the build cache node with its default configuration. This configuration allows anonymous access to the configuration user interface and anonymous write access to…
ModificadaAlta (7.5)2.9%—Squid-cache SquidFedoraproject Fedora18/10/202117/6/2026
An issue was discovered in Squid 5.0.6 through 5.1.x before 5.2. When validating an origin server or peer certificate, Squid may incorrectly classify certain certificates as trusted. This problem allows a remote server to obtain security trust well improperly. This indication of trust may be passed along to clients,…
ModificadaMedia (6.5)8.2%💥 ExploitChachethq Cachet26/8/202117/6/2026
Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in the `SearchableTrait#scopeSearch()`. Attackers without authentication can utilize this vulnerability to exfiltrate sensitive data from the database such as administrator's password and session. The…
ModificadaMedia (4.3)6.1%💥 ExploitPhpfastcache12/8/202117/6/2026
PhpFastCache is a high-performance backend cache system (packagist package phpfastcache/phpfastcache). In versions before 6.1.5, 7.1.2, and 8.0.7 the `phpinfo()` can be exposed if the `/vendor` is not protected from public access. This is a rare situation today since the vendor directory is often located outside the…
ModificadaAlta (8.1)1.1%—Cache Project Cache8/8/202117/6/2026
An issue was discovered in the cache crate through 2020-11-24 for Rust. There are unconditional implementations of Send and Sync for Cache<K>.
ModificadaMedia (6.1)1.9%💥 ExploitBoldgrid W3 Total Cache19/7/202117/6/2026
The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the 'Anonymously track usage to improve product quality' setting is enabled, as the parameter is output in a JavaScript context without proper…
ModificadaMedia (6.1)1.9%💥 ExploitBoldgrid W3 Total Cache19/7/202117/6/2026
The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability within the "extension" parameter in the Extensions dashboard, which is output in an attribute without being escaped first. This could allow an attacker, who can convince an authenticated…
ModificadaMedia (6.5)1.6%—Varnish-cache Varnish CacheVarnish-software Varnish CacheVarnish Cache Project Varnish CacheFedoraproject Fedora+114/7/202117/6/2026
Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x before 6.6.1, and 6.0 LTS before 6.0.8.
ModificadaMedia (4.8)0.62%—Boldgrid W3 Total Cache12/7/202117/6/2026
The W3 Total Cache WordPress plugin before 2.1.3 did not sanitise or escape some of its CDN settings, allowing high privilege users to use JavaScript in them, which will be output in the page, leading to an authenticated Stored Cross-Site Scripting issue
ModificadaMedia (6.5)16%—Squid-cache SquidFedoraproject FedoraNetapp Cloud Manager8/6/202117/6/2026
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent.
ModificadaMedia (5.4)4.5%—Automattic WP Super Cache1/6/202117/6/2026
The WP Super Cache WordPress plugin before 1.7.3 did not properly sanitise its wp_cache_location parameter in its settings, which could lead to a Stored Cross-Site Scripting issue.
ModificadaAlta (7.2)1.9%—Automattic WP Super Cache1/6/202117/6/2026
The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of WP Super Cache WordPress plugin before 1.7.3 result in RCE because they allow input of '$' and '\n'. This is due to an incomplete fix of CVE-2021-24209.
ModificadaMedia (6.5)80%—Squid-cache SquidFedoraproject FedoraDebian Linux28/5/202117/6/2026
Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTP response. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent by the server.
ModificadaMedia (6.5)5.3%—Squid-cache SquidDebian LinuxNetapp Cloud ManagerFedoraproject Fedora27/5/202117/6/2026
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to an input-validation bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy). A client sends an HTTP Range request to trigger this.
ModificadaMedia (6.5)96%—Squid-cache SquidDebian LinuxFedoraproject FedoraNetapp Cloud Manager27/5/202117/6/2026
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy) via HTTP Range request processing.
Orbitaley — Vulnerabilidades