Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2899▼ 147 respecto a la semana anterior
Críticas / altas1291▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

458 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (10)0.57%—Boldgrid W3 Total CacheAI19/8/202626/8/2026
The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name. On Apache, the…
AplazadaAlta (7.2)0.43%—Boldgrid W3 Total CacheAI14/8/202614/8/2026
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will…
AplazadaAlta (7.2)0.38%—Camaleon AttackAICamaleon Front CacheAICamaleon Cama Meta TAGAICamaleon Cama Contact FormAI+112/8/202626/8/2026
CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorization. Attackers can manipulate plugin configuration parameters at runtime…
AplazadaAlta (8.7)0.80%—CachetAI10/8/202624/9/2026
Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code. Attackers can create malicious incident templates with Blade directives or Twig filters that execute system commands when incidents are created,…
AplazadaMedia (6.5)0.41%—W3 Total CacheAI6/8/202612/8/2026
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
AplazadaMedia (4.7)0.29%—Clearfy CacheAI4/8/202626/8/2026
The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect handler, passing a decoded request URI to an unsafe redirect function, which allows unauthenticated attackers to redirect visitors to an arbitrary external URL when a non-default option is enabled.
AplazadaMedia (4.3)0.27%—Clearfy CacheAI4/8/202626/8/2026
The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch paths, allowing any authenticated user such as a Subscriber to render admin-only settings pages and disclose their contents, including administrative nonces, while the canonical page URL correctly…
AplazadaMedia (4.1)0.37%—Clearfy CacheAI3/8/202626/8/2026
The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain is present in the environment.
AplazadaMedia (4.9)0.50%—Softaculous SpeedycacheAI28/7/202629/7/2026
The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and including, 1.3.8. This is due to a mismatch between CSS URL validation (which allows query strings like `.css?...`) and path resolution (which strips query strings), combined with no validation that…
AplazadaCrítica (9.8)0.52%—Regularlabs Cache Cleaner PROAIJoomlaAI23/7/202627/7/2026
Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs.
AplazadaCrítica (9.8)0.48%—JoomlaAIRegularlabs Cache Cleaner PROAI23/7/202624/7/2026
Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.
AplazadaMedia (6.5)0.33%—Regularlabs Cache Cleaner PROAIJoomlaAI23/7/202624/7/2026
Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directory.
AplazadaMedia (5.4)0.13%—Regularlabs Cache CleanerAI23/7/202624/7/2026
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not consistently require a valid token and cache-management permission.
AplazadaCrítica (9.3)1.1%—Kvcache-ai KtransformersAI20/7/202623/7/2026
ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER socket bound to all interfaces. Attackers can exploit malicious…
AnalizadaMedia (5.5)2.7%—Squid-cache Squid16/7/202620/7/2026
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in src/peer_digest.cc), Squid is vulnerable to a heap-based buffer overflow: a cache digest's on-the-wire size may be larger than the mask_size declared within the digest, so…
AnalizadaMedia (6.5)2.4%—Squid-cache Squid16/7/202620/7/2026
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename,…
AplazadaMedia (4.3)0.39%—Cache PurgerAI16/7/202616/7/2026
The The Cache Purger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.20. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to…
AplazadaMedia (6.1)0.25%—Breeze CacheAI13/7/202613/7/2026
The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by…
AplazadaAlta (7.5)2.9%—Boldgrid W3 Total CacheAI11/7/202614/7/2026
The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation…
AplazadaCrítica (9)0.53%—W3 Total CacheAI2/7/20262/7/2026
Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.
AplazadaAlta (7.5)0.42%—Object Cache 4 EveryoneAI26/6/202626/6/2026
Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions.
AplazadaMedia (4.7)0.29%—Boldgrid W3 Total CacheAI17/6/202617/6/2026
Author Broken Access Control in W3 Total Cache <= 2.9.1 versions.
AplazadaBaja (1.1)0.07%—LmcacheAI4/6/202622/7/2026
A flaw has been found in LMCache up to 0.4.6. This affects the function hex_hash_to_int16 of the file lmcache/integration/vllm/utils.py of the component KV Cache Handler. Executing a manipulation can lead to use of weak hash. The attack needs to be launched locally. The attack requires a high level of complexity. It…
AplazadaBaja (1.1)0.07%—Zilliztech GptcacheAI4/6/202622/7/2026
A vulnerability was detected in zilliztech GPTCache up to 0.1.44. Affected by this issue is the function BufferedReader.peek of the file gptcache/processor/pre.py of the component Cache Key Handler. Performing a manipulation of the argument input_data["image"] results in use of weak hash. The attack must be initiated…
Pendiente de análisisBaja (2.3)0.47%—Varnish CacheAIVinyl-cache Vinyl CacheAI3/6/202622/7/2026
In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync attack (request smuggling), which in turn can be used for cache poisoning, authentication bypass, or possibly even information disclosure and manipulation. The attack…