Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
463 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.9% | — | Automattic WP Super Cache | 1/6/2021 | 17/6/2026 | The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of WP Super Cache WordPress plugin before 1.7.3 result in RCE because they allow input of '$' and '\n'. This is due to an incomplete fix of CVE-2021-24209. | |
| Modificada | Media (6.5) | 80% | — | Squid-cache SquidFedoraproject FedoraDebian Linux | 28/5/2021 | 17/6/2026 | Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTP response. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent by the server. | |
| Modificada | Media (6.5) | 5.3% | — | Squid-cache SquidDebian LinuxNetapp Cloud ManagerFedoraproject Fedora | 27/5/2021 | 17/6/2026 | An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to an input-validation bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy). A client sends an HTTP Range request to trigger this. | |
| Modificada | Media (6.5) | 96% | — | Squid-cache SquidDebian LinuxFedoraproject FedoraNetapp Cloud Manager | 27/5/2021 | 17/6/2026 | An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy) via HTTP Range request processing. | |
| Modificada | Media (6.5) | 72% | — | Squid-cache SquidDebian LinuxFedoraproject Fedora | 27/5/2021 | 17/6/2026 | An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a certain response header over HTTP or HTTPS, there is a denial of service. This header can plausibly occur in benign network traffic. | |
| Modificada | Media (4.9) | 4.3% | — | Squid-cache SquidDebian LinuxFedoraproject Fedora | 27/5/2021 | 17/6/2026 | An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to incorrect parser validation, it allows a Denial of Service attack against the Cache Manager API. This allows a trusted client to trigger memory leaks that. over time, lead to a Denial of Service via an unspecified short query string. This attack… | |
| Modificada | Alta (7.5) | 7.4% | — | Squid-cache SquidDebian LinuxFedoraproject FedoraNetapp Cloud Manager | 27/5/2021 | 17/6/2026 | An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a buffer-management bug, it allows a denial of service. When resolving a request with the urn: scheme, the parser leaks a small amount of memory. However, there is an unspecified attack methodology that can easily trigger a large amount of… | |
| Modificada | Media (6.5) | 2.6% | — | Wpfastestcache WP Fastest Cache | 27/4/2021 | 17/6/2026 | Directory traversal vulnerability in WP Fastest Cache versions prior to 0.9.1.7 allows a remote attacker with administrator privileges to delete arbitrary files on the server via unspecified vectors. | |
| Modificada | Alta (7.2) | 28% | — | Automattic WP Super Cache | 5/4/2021 | 17/6/2026 | The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option. Direct access to the wp-cache-config.php file is not prohibited, so this vulnerability… | |
| Modificada | Alta (8.6) | 7.3% | — | Squid-cache SquidDebian LinuxFedoraproject FedoraNetapp Cloud Manager | 19/3/2021 | 17/6/2026 | An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access services otherwise forbidden by the security controls. This occurs for certain uri_whitespace configuration settings. | |
| Modificada | Alta (7.5) | 1.5% | — | Varnish-cache Varnish-modulesVarnish-cache Varnish-modules KlarlackFedoraproject Fedora | 16/3/2021 | 17/6/2026 | Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not affect organizations that only install the Varnish Cache product; however, it is common to install both Varnish Cache and varnish-modules. Specifically, an assertion failure… | |
| Modificada | Media (5.3) | 13% | — | Squid-cache SquidFedoraproject FedoraDebian Linux | 9/3/2021 | 17/6/2026 | Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody. | |
| Modificada | Alta (7.5) | 1.4% | — | Cache Project Cache | 26/1/2021 | 17/6/2026 | An issue was discovered in the cache crate through 2021-01-01 for Rust. A raw pointer is dereferenced. | |
| Modificada | Media (6.1) | 0.94% | — | Litespeedtech Litespeed Cache | 26/12/2020 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting. | |
| Modificada | Crítica (9.8) | 2.2% | — | Memcached Docker Image | 17/12/2020 | 17/6/2026 | The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. System using the memcached docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Alta (7.5) | 1.0% | — | Gradle EnterpriseGradle Enterprise Cache Node | 18/9/2020 | 17/6/2026 | An issue was discovered in Gradle Enterprise 2018.2 and Gradle Enterprise Build Cache Node 4.1. Cross-site transmission of cookie containing CSRF token allows remote attacker to bypass CSRF mitigation. | |
| Modificada | Alta (7.5) | 1.7% | — | Gradle EnterpriseGradle Enterprise Cache Node | 18/9/2020 | 17/6/2026 | An issue was discovered in Gradle Enterprise 2017.3 - 2020.2.4 and Gradle Enterprise Build Cache Node 1.0 - 9.2. Unrestricted HTTP header reflection in Gradle Enterprise allows remote attackers to obtain authentication cookies, if they are able to discover a separate XSS vulnerability. This potentially allows an… | |
| Modificada | Media (6.5) | 4.1% | — | Squid-cache SquidCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+1 | 2/9/2020 | 17/6/2026 | An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitting attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser scripts, to bypass local security and poison the browser cache and any… | |
| Modificada | Media (6.5) | 2.4% | — | Squid-cache SquidCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+1 | 2/9/2020 | 17/6/2026 | An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Smuggling attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser scripts, to bypass local security and poison the proxy cache and any… | |
| Modificada | Alta (7.5) | 5.0% | — | Squid-cache SquidCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+1 | 24/8/2020 | 17/6/2026 | Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer is used with the cache digests feature. The problem exists because peerDigestHandleReply()… | |
| Modificada | Media (6.5) | 4.4% | — | Squid-cache Squid | 30/6/2020 | 17/6/2026 | An issue was discovered in Squid 5.x before 5.0.3. Due to an Incorrect Synchronization, a Denial of Service can occur when processing objects in an SMP cache because of an Ipc::Mem::PageStack::pop ABA problem during access to the memory page/slot management list. | |
| Modificada | Alta (7.5) | 2.5% | — | Squid-cache SquidFedoraproject FedoraNetapp Cloud Manager | 30/6/2020 | 17/6/2026 | An issue was discovered in Squid before 4.12 and 5.x before 5.0.3. Due to use of a potentially dangerous function, Squid and the default certificate validation helper are vulnerable to a Denial of Service when opening a TLS connection to an attacker-controlled server for HTTPS. This occurs because unrecognized error… | |
| Modificada | Alta (8.8) | 5.7% | — | Squid-cache SquidFedoraproject Fedora | 30/6/2020 | 17/6/2026 | An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggling and Poisoning attack can succeed against the HTTP cache. The client sends an HTTP request with a Content-Length header containing "+\ "-" or an uncommon shell whitespace character prefix to the… | |
| Modificada | Crítica (9.8) | 27% | — | Squid-cache SquidDebian LinuxOpensuse LeapFedoraproject Fedora+1 | 23/4/2020 | 17/6/2026 | An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token… | |
| Modificada | Alta (7.5) | 3.9% | — | Squid-cache SquidCanonical Ubuntu LinuxDebian Linux | 15/4/2020 | 17/6/2026 | An issue was discovered in Squid through 4.7 and 5. When receiving a request, Squid checks its cache to see if it can serve up a response. It does this by making a MD5 hash of the absolute URL of the request. If found, it servers the request. The absolute URL can include the decoded UserInfo (username and password)… |