Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

463 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)20%—Squid-cache SquidCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+126/11/201917/6/2026
An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remote server in response to an URN request, Squid fails to ensure that the response can fit within the buffer. This leads to attacker controlled data overflowing in the…
ModificadaCrítica (9.1)4.3%—Squid-cache SquidCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+126/11/201917/6/2026
An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes all access checks to be bypassed and allows access to restricted HTTP servers, e.g., an attacker can…
ModificadaAlta (7.5)2.1%—Boldgrid W3 Total Cache22/11/201916/6/2026
W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via their hash keys.
ModificadaAlta (7.5)2.3%—Boldgrid W3 Total Cache22/11/201916/6/2026
W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.
ModificadaAlta (7.5)5.4%—Boldgrid W3 Total Cache22/11/201916/6/2026
W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.
ModificadaAlta (7.5)5.8%—Varnish-software Varnish CacheVarnish Cache Project Varnish CacheDebian Linux3/9/201917/6/2026
An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests. The assert will cause an automatic restart with a clean cache, which makes it a Denial of Service attack.
ModificadaAlta (7.5)2.6%—Memcached30/8/201917/6/2026
memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c.
ModificadaAlta (7.5)12%—Squid-cache SquidDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+115/8/201917/6/2026
Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with memory access protections, this can cause the CGI process to terminate unexpectedly, resulting in a denial of service for all clients using it.
ModificadaCrítica (9.8)3.0%—Wpfastestcache WP Fastest Cache14/8/201917/6/2026
The wp-fastest-cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin/admin-ajax.php?action=wpfc_wppolls_ajax_request via the poll_id parameter.
ModificadaAlta (7.8)2.1%—Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+515/8/201917/6/2026
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
ModificadaCrítica (9.1)44%—Wpfastestcache WP Fastest Cache30/7/201917/6/2026
The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.php Directory Traversal.
ModificadaMedia (6.5)4.3%—Wpfastestcache WP Fastest Cache29/7/201917/6/2026
The WP Fastest Cache plugin through 0.8.9.0 for WordPress allows remote attackers to delete arbitrary files because wp_postratings_clear_fastest_cache and rm_folder_recursively in wpFastestCache.php mishandle ../ in an HTTP Referer header.
ModificadaMedia (5.9)8.1%—Squid-cache SquidDebian LinuxFedoraproject FedoraOpensuse Leap+111/7/201917/6/2026
An issue was discovered in Squid 2.x through 2.7.STABLE9, 3.x through 3.5.28, and 4.x through 4.7. When Squid is configured to use Basic Authentication, the Proxy-Authorization header is parsed via uudecode. uudecode determines how many bytes will be decoded by iterating over the input and checking its table. The…
ModificadaAlta (8.8)49%—Squid-cache SquidFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+411/7/201917/6/2026
An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the decoded data. Squid does not check that the decoded length isn't greater than the buffer, leading to a heap-based buffer overflow with user controlled data.
ModificadaCrítica (9.8)24%—Squid-cache SquidDebian LinuxOpensuse LeapFedoraproject Fedora+111/7/201917/6/2026
An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authentication, it parses the header Proxy-Authorization. It searches for certain tokens such as domain, uri, and qop. Squid checks if this token's value starts with a quote and ends with one. If so, it…
ModificadaMedia (6.4)0.72%—Intersystems Cache11/7/201917/6/2026
Intersystems Cache 2017.2.2.865.0 allows XXE.
ModificadaMedia (5.4)0.70%—Intersystems Cache11/7/201917/6/2026
Intersystems Cache 2017.2.2.865.0 has Incorrect Access Control.
ModificadaMedia (6.1)0.90%—Intersystems Cache11/7/201917/6/2026
Intersystems Cache 2017.2.2.865.0 allows XSS.
ModificadaMedia (6.1)74%—Squid-cache SquidDebian Linux5/7/201917/6/2026
The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.
ModificadaMedia (5.6)0.61%—Intel Microarchitectural Data Sampling Uncacheable Memory FirmwareFedoraproject Fedora30/5/201917/6/2026
Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable memory on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here:…
ModificadaAlta (7.5)3.0%—MemcachedCanonical Ubuntu Linux29/4/201917/6/2026
In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in memcached.c.
ModificadaCrítica (9.8)1.2%—Gradle Build Cache NodeGradle Enterprise22/4/201917/6/2026
In Gradle Enterprise before 2018.5.2, Build Cache Nodes would reflect the configured password back when viewing the HTML page source of the settings page.
ModificadaMedia (6.1)1.4%—Wpfastestcache WP Fastest Cache15/4/201917/6/2026
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_timeout_pages action.
ModificadaMedia (6.1)1.4%—Wpfastestcache WP Fastest Cache15/4/201917/6/2026
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the wpfastestcacheoptions wpFastestCachePreload_number or wpFastestCacheLanguage parameter.
ModificadaAlta (8.8)0.92%—Wpfastestcache WP Fastest Cache15/4/201917/6/2026
The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcacheoptions page.
Orbitaley — Vulnerabilidades