Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
463 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.4% | — | Wpfastestcache WP Fastest Cache | 15/4/2019 | 17/6/2026 | The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_exclude_pages action. | |
| Modificada | Alta (7.5) | 19% | 💥 Exploit | Boldgrid W3 Total Cache | 1/4/2019 | 17/6/2026 | pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data. | |
| Modificada | Alta (8.8) | 1.6% | — | Ipycache Project Ipycache | 21/3/2019 | 17/6/2026 | A code injection issue was discovered in ipycache through 2016-05-31. | |
| Modificada | Media (6.9) | 1.3% | — | Oracle WEB Cache | 16/1/2019 | 17/6/2026 | Vulnerability in the Oracle Web Cache component of Oracle Fusion Middleware (subcomponent: ESI/Partial Page Caching). The supported version that is affected is 11.1.1.9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Cache. Successful attacks… | |
| Modificada | Media (5.9) | 6.1% | — | Squid-cache SquidDebian Linux | 9/11/2018 | 17/6/2026 | Squid before 4.4, when SNMP is enabled, allows a denial of service (Memory Leak) via an SNMP packet. | |
| Modificada | Media (6.1) | 3.3% | 💥 PoC | Squid-cache Squid | 9/11/2018 | 17/6/2026 | Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors. | |
| Modificada | Alta (7.5) | 2.1% | — | Cached-path-relative Project Cached-path-relativeDebian Linux | 6/11/2018 | 17/6/2026 | A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype chain causing a DoS attack. | |
| Modificada | Crítica (9.8) | 1.8% | — | Pivotal Software Cloud Foundry LOG Cache | 5/10/2018 | 17/6/2026 | Cloud Foundry Log Cache, versions prior to 1.1.1, logs its UAA client secret on startup as part of its envstruct report. A remote attacker who has gained access to the Log Cache VM can read this secret, gaining all privileges held by the Log Cache UAA client. In the worst case, if this client is an admin, the attacker… | |
| Modificada | Alta (8.8) | 0.96% | — | Pivotal Software Pivotal Cloud Cache | 17/9/2018 | 17/6/2026 | Pivotal Cloud Cache, versions prior to 1.3.1, prints a superuser password in plain text during BOSH deployment logs. A malicious user with access to the logs could escalate their privileges using this password. | |
| Modificada | Media (5.9) | 8.3% | — | Squid-cache Squid | 16/5/2018 | 17/6/2026 | This vulnerability allows remote attackers to deny service on vulnerable installations of The Squid Software Foundation Squid 3.5.27-20180318. Authentication is not required to exploit this vulnerability. The specific flaw exists within ClientRequestContext::sslBumpAccessCheck(). A crafted request can trigger the… | |
| Modificada | Alta (7.5) | 2.3% | — | MemcachedDebian LinuxCanonical Ubuntu LinuxRedhat Openstack | 13/3/2018 | 17/6/2026 | memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service. This… | |
| Modificada | Alta (7.5) | 88% | 💥 Exploit | MemcachedCanonical Ubuntu LinuxDebian LinuxRedhat Openstack | 5/3/2018 | 17/6/2026 | Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources). This attack… | |
| Modificada | Alta (7.5) | 13% | — | Squid-cache SquidDebian LinuxCanonical Ubuntu Linux | 9/2/2018 | 17/6/2026 | The Squid Software Foundation Squid HTTP Caching Proxy version prior to version 4.0.23 contains a NULL Pointer Dereference vulnerability in HTTP Response X-Forwarded-For header processing that can result in Denial of Service to all clients of the proxy. This attack appear to be exploitable via Remote HTTP server… | |
| Modificada | Alta (7.5) | 7.9% | — | Squid-cache SquidDebian LinuxCanonical Ubuntu Linux | 9/2/2018 | 17/6/2026 | The Squid Software Foundation Squid HTTP Caching Proxy version 3.0 to 3.5.27, 4.0 to 4.0.22 contains a Incorrect Pointer Handling vulnerability in ESI Response Processing that can result in Denial of Service for all clients using the proxy.. This attack appear to be exploitable via Remote server delivers an HTTP… | |
| Modificada | Crítica (9.1) | 4.1% | — | Varnish-cache VarnishVarnish Cache Project Varnish CacheDebian Linux | 16/11/2017 | 17/6/2026 | vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a VFP_GetStorage buffer is larger than intended in certain circumstances involving -sfile Stevedore transient objects. | |
| Modificada | Alta (8.8) | 0.99% | — | Wpfastestcache WP Fastest Cache | 19/9/2017 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the optionsPageRequest function in admin.php in WP Fastest Cache plugin before 0.8.3.5 for WordPress allow remote attackers to hijack the authentication of unspecified victims for requests that call the (1) saveOption, (2) deleteCache, (3)… | |
| Modificada | Alta (7.8) | 0.39% | — | Open-uri-cached Project Open-uri-cached | 18/8/2017 | 17/6/2026 | The open-uri-cached rubygem allows local users to execute arbitrary Ruby code by creating a directory under /tmp containing "openuri-" followed by a crafted UID, and putting Ruby code in said directory once a meta file is created. | |
| Modificada | Alta (7.5) | 2.4% | — | Varnish-cache VarnishVarnish Cache Project Varnish CacheVarnish-software Varnish Cache | 4/8/2017 | 17/6/2026 | An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2. A wrong if statement in the varnishd source code means that particular invalid requests from the client can trigger an assert, related to an Integer Overflow. This causes the varnishd worker process… | |
| Modificada | Alta (7.5) | 4.2% | — | Memcached | 17/7/2017 | 17/6/2026 | The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a comparison between signed and unsigned int and triggers a heap-based buffer over-read. NOTE: this vulnerability exists because… | |
| Modificada | Alta (7.5) | 1.3% | — | Bluecoat Advanced Secure GatewayBluecoat CacheflowBluecoat Proxysg | 8/6/2017 | 17/6/2026 | Blue Coat Advanced Secure Gateway 6.6, CacheFlow 3.4, ProxySG 6.5 and 6.6 allows remote attackers to bypass blocked requests, user authentication, and payload scanning. | |
| Modificada | Baja (3.3) | 0.32% | — | Libmenu-cache Project Libmenu-cache | 15/5/2017 | 17/6/2026 | Libmenu-cache 1.0.2 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (menu unavailability). | |
| Modificada | Media (6.1) | 0.71% | — | Apt-cacher-ng Project Apt-cacher-ngApt-cacher Project Apt-cacher | 5/4/2017 | 17/6/2026 | apt-cacher before 1.7.15 and apt-cacher-ng before 3.4 allow HTTP response splitting via encoded newline characters, related to lack of blocking for the %0[ad] regular expression. | |
| Modificada | Crítica (9.8) | 12% | 💥 PoC | Phpmemcachedadmin Project Phpmemcachedadmin | 23/3/2017 | 17/6/2026 | PHPMemcachedAdmin 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via vectors related "serialized data and the last part of the concatenated filename," which creates a file in webroot. | |
| Modificada | Alta (7.5) | 4.8% | — | Squid-cache Squid | 27/1/2017 | 17/6/2026 | Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple clients. | |
| Modificada | Alta (7.5) | 6.8% | — | Debian LinuxSquid-cache Squid | 27/1/2017 | 17/6/2026 | Incorrect processing of responses to If-None-Modified HTTP conditional requests in Squid HTTP Proxy 3.1.10 through 3.1.23, 3.2.0.3 through 3.5.22, and 4.0.1 through 4.0.16 leads to client-specific Cookie data being leaked to other clients. Attack requests can easily be crafted by a client to probe a cache for this… |