Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2899▼ 147 respecto a la semana anterior
Críticas / altas1291▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
458 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 0.57% | — | Boldgrid W3 Total CacheAI | 19/8/2026 | 26/8/2026 | The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name. On Apache, the… | |
| Aplazada | Alta (7.2) | 0.43% | — | Boldgrid W3 Total CacheAI | 14/8/2026 | 14/8/2026 | The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Alta (7.2) | 0.38% | — | Camaleon AttackAICamaleon Front CacheAICamaleon Cama Meta TAGAICamaleon Cama Contact FormAI+1 | 12/8/2026 | 26/8/2026 | CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorization. Attackers can manipulate plugin configuration parameters at runtime… | |
| Aplazada | Alta (8.7) | 0.80% | — | CachetAI | 10/8/2026 | 24/9/2026 | Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code. Attackers can create malicious incident templates with Blade directives or Twig filters that execute system commands when incidents are created,… | |
| Aplazada | Media (6.5) | 0.41% | — | W3 Total CacheAI | 6/8/2026 | 12/8/2026 | Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions. | |
| Aplazada | Media (4.7) | 0.29% | — | Clearfy CacheAI | 4/8/2026 | 26/8/2026 | The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect handler, passing a decoded request URI to an unsafe redirect function, which allows unauthenticated attackers to redirect visitors to an arbitrary external URL when a non-default option is enabled. | |
| Aplazada | Media (4.3) | 0.27% | — | Clearfy CacheAI | 4/8/2026 | 26/8/2026 | The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch paths, allowing any authenticated user such as a Subscriber to render admin-only settings pages and disclose their contents, including administrative nonces, while the canonical page URL correctly… | |
| Aplazada | Media (4.1) | 0.37% | — | Clearfy CacheAI | 3/8/2026 | 26/8/2026 | The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain is present in the environment. | |
| Aplazada | Media (4.9) | 0.50% | — | Softaculous SpeedycacheAI | 28/7/2026 | 29/7/2026 | The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and including, 1.3.8. This is due to a mismatch between CSS URL validation (which allows query strings like `.css?...`) and path resolution (which strips query strings), combined with no validation that… | |
| Aplazada | Crítica (9.8) | 0.52% | — | Regularlabs Cache Cleaner PROAIJoomlaAI | 23/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs. | |
| Aplazada | Crítica (9.8) | 0.48% | — | JoomlaAIRegularlabs Cache Cleaner PROAI | 23/7/2026 | 24/7/2026 | Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services. | |
| Aplazada | Media (6.5) | 0.33% | — | Regularlabs Cache Cleaner PROAIJoomlaAI | 23/7/2026 | 24/7/2026 | Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directory. | |
| Aplazada | Media (5.4) | 0.13% | — | Regularlabs Cache CleanerAI | 23/7/2026 | 24/7/2026 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not consistently require a valid token and cache-management permission. | |
| Aplazada | Crítica (9.3) | 1.1% | — | Kvcache-ai KtransformersAI | 20/7/2026 | 23/7/2026 | ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER socket bound to all interfaces. Attackers can exploit malicious… | |
| Analizada | Media (5.5) | 2.7% | — | Squid-cache Squid | 16/7/2026 | 20/7/2026 | Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in src/peer_digest.cc), Squid is vulnerable to a heap-based buffer overflow: a cache digest's on-the-wire size may be larger than the mask_size declared within the digest, so… | |
| Analizada | Media (6.5) | 2.4% | — | Squid-cache Squid | 16/7/2026 | 20/7/2026 | Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename,… | |
| Aplazada | Media (4.3) | 0.39% | — | Cache PurgerAI | 16/7/2026 | 16/7/2026 | The The Cache Purger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.20. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Aplazada | Media (6.1) | 0.25% | — | Breeze CacheAI | 13/7/2026 | 13/7/2026 | The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by… | |
| Aplazada | Alta (7.5) | 2.9% | — | Boldgrid W3 Total CacheAI | 11/7/2026 | 14/7/2026 | The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation… | |
| Aplazada | Crítica (9) | 0.53% | — | W3 Total CacheAI | 2/7/2026 | 2/7/2026 | Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Object Cache 4 EveryoneAI | 26/6/2026 | 26/6/2026 | Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions. | |
| Aplazada | Media (4.7) | 0.29% | — | Boldgrid W3 Total CacheAI | 17/6/2026 | 17/6/2026 | Author Broken Access Control in W3 Total Cache <= 2.9.1 versions. | |
| Aplazada | Baja (1.1) | 0.07% | — | LmcacheAI | 4/6/2026 | 22/7/2026 | A flaw has been found in LMCache up to 0.4.6. This affects the function hex_hash_to_int16 of the file lmcache/integration/vllm/utils.py of the component KV Cache Handler. Executing a manipulation can lead to use of weak hash. The attack needs to be launched locally. The attack requires a high level of complexity. It… | |
| Aplazada | Baja (1.1) | 0.07% | — | Zilliztech GptcacheAI | 4/6/2026 | 22/7/2026 | A vulnerability was detected in zilliztech GPTCache up to 0.1.44. Affected by this issue is the function BufferedReader.peek of the file gptcache/processor/pre.py of the component Cache Key Handler. Performing a manipulation of the argument input_data["image"] results in use of weak hash. The attack must be initiated… | |
| Pendiente de análisis | Baja (2.3) | 0.47% | — | Varnish CacheAIVinyl-cache Vinyl CacheAI | 3/6/2026 | 22/7/2026 | In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync attack (request smuggling), which in turn can be used for cache poisoning, authentication bypass, or possibly even information disclosure and manipulation. The attack… |