Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
463 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 6.7% | — | Squid-cache SquidDebian LinuxCanonical Ubuntu LinuxOpensuse Leap | 15/4/2020 | 17/6/2026 | An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it's being evaluated. When processing the expression, it could either evaluate the top of the stack, or add a new… | |
| Modificada | Crítica (9.8) | 3.9% | — | Squid-cache SquidDebian LinuxCanonical Ubuntu Linux | 15/4/2020 | 17/6/2026 | An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid by default comes with rules to block access to the Cache Manager, which serves detailed server information meant for the maintainer. This rule is implemented via… | |
| Modificada | Media (4.5) | 0.34% | — | Squid-cache Squid | 15/4/2020 | 17/6/2026 | An issue was discovered in Squid through 4.7. When Squid is run as root, it spawns its child processes as a lesser user, by default the user nobody. This is done via the leave_suid call. leave_suid leaves the Saved UID as 0. This makes it trivial for an attacker who has compromised the child process to escalate their… | |
| Modificada | Media (5.9) | 5.9% | — | Squid-cache SquidCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 15/4/2020 | 17/6/2026 | An issue was discovered in Squid through 4.7. When Squid is parsing ESI, it keeps the ESI elements in ESIContext. ESIContext contains a buffer for holding a stack of ESIElements. When a new ESIElement is parsed, it is added via addStackElement. addStackElement has a check for the number of elements in this buffer, but… | |
| Modificada | Alta (7.5) | 2.2% | — | Varnish-cache Varnish CacheVarnish-software Varnish CacheOpensuse Backports SLEOpensuse Leap+1 | 8/4/2020 | 17/6/2026 | An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss. | |
| Modificada | Alta (7.5) | 1.8% | — | Varnish-cache Varnish CacheVarnish-software Varnish CacheOpensuse Backports SLEOpensuse Leap | 8/4/2020 | 17/6/2026 | An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such… | |
| Modificada | Alta (7.5) | 28% | — | Memcached | 24/3/2020 | 17/6/2026 | Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to try_read_command_binary in memcached.c. | |
| Modificada | Media (6.1) | 5.5% | — | Squid-cache SquidDebian LinuxCanonical Ubuntu LinuxOpensuse Leap | 20/3/2020 | 17/6/2026 | Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi. | |
| Modificada | Alta (7.5) | 1.3% | — | Varnish Cache Project Varnish Cache | 12/2/2020 | 16/6/2026 | Varnish HTTP cache before 3.0.4: ACL bug | |
| Modificada | Crítica (9.8) | 74% | 💥 Exploit | Automattic WP Super CacheBoldgrid W3 Total Cache | 12/2/2020 | 16/6/2026 | WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 13% | 💥 Exploit | Automattic WP Super Cache | 7/2/2020 | 16/6/2026 | WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution | |
| Modificada | Media (6.1) | 1.5% | — | Automattic WP Super Cache | 7/2/2020 | 16/6/2026 | WordPress Super Cache Plugin 1.3 has XSS. | |
| Modificada | Alta (7.5) | 10% | — | Squid-cache SquidFedoraproject FedoraDebian LinuxOpensuse Leap+1 | 4/2/2020 | 17/6/2026 | An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid processes. | |
| Modificada | Alta (7.5) | 6.8% | — | Squid-cache SquidOpensuse LeapCanonical Ubuntu Linux | 4/2/2020 | 17/6/2026 | An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials parser in ext_lm_group_acl may write to memory outside the credentials buffer. On systems with memory access protections, this can result in the helper process being terminated unexpectedly. This leads… | |
| Modificada | Alta (7.3) | 72% | — | Squid-cache SquidCanonical Ubuntu LinuxOpensuse LeapFedoraproject Fedora+1 | 4/2/2020 | 17/6/2026 | An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy. | |
| Modificada | Alta (7.5) | 8.3% | — | Squid-cache SquidDebian LinuxCanonical Ubuntu LinuxOpensuse Leap+1 | 4/2/2020 | 17/6/2026 | An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access server resources prohibited by earlier security filters. | |
| Modificada | Media (5.5) | 0.26% | — | Apt-cacher-ng Project Apt-cacher-ngOpensuse Backports | 23/1/2020 | 17/6/2026 | The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root privileges. This can allow local attackers to influence the outcome of these operations. This issue affects: openSUSE Leap 15.1 apt-cacher-ng versions prior to 3.1-lp151.3.3.1. | |
| Modificada | Media (5.5) | 0.47% | — | Apt-cacher-ng Project Apt-cacher-ngDebian LinuxOpensuse BackportsOpensuse Leap | 21/1/2020 | 17/6/2026 | apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to apt-cacher-ng via TCP on localhost port 3142, even if the explicit SocketPath=/var/run/apt-cacher-ng/socket command-line option is passed.… | |
| Modificada | Crítica (9.8) | 3.5% | — | Devcert-sanscache Project Devcert-sanscache | 8/1/2020 | 17/6/2026 | devcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the exec function. The variable `commonName` controlled by user input is used as part of the `exec` function without any sanitization. | |
| Modificada | Alta (8.8) | 5.1% | — | Automattic W3 Super Cache | 26/12/2019 | 16/6/2026 | WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code. This issue exists because of an incomplete fix for CVE-2013-2009. | |
| Modificada | Crítica (9.8) | 1.2% | — | Phpfastcache | 12/12/2019 | 17/6/2026 | In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver. | |
| Modificada | Alta (7.5) | 41% | — | Squid-cache SquidCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora | 26/11/2019 | 17/6/2026 | An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR… | |
| Modificada | Media (5.3) | 6.2% | — | Squid-cache SquidCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora | 26/11/2019 | 17/6/2026 | An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Response messages corrupt caches (between a client and Squid) with attacker-controlled content at… | |
| Modificada | Media (6.1) | 7.2% | — | Squid-cache SquidCanonical Ubuntu LinuxFedoraproject Fedora | 26/11/2019 | 17/6/2026 | An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately redirect traffic to origins it should not be delivered to. | |
| Modificada | Alta (7.5) | 9.2% | — | Squid-cache SquidCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux | 26/11/2019 | 17/6/2026 | An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there is a heap-based buffer overflow that can result in Denial of Service to all clients using the proxy. Severity is high due to this vulnerability occurring before normal security checks; any remote client that can reach… |