Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Varnish Cache Project Varnish Cache | 12/2/2020 | 16/6/2026 | Varnish HTTP cache before 3.0.4: ACL bug | |
| Modificada | Alta (7.5) | 5.8% | — | Varnish-software Varnish CacheVarnish Cache Project Varnish CacheDebian Linux | 3/9/2019 | 17/6/2026 | An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests. The assert will cause an automatic restart with a clean cache, which makes it a Denial of Service attack. | |
| Modificada | Crítica (9.1) | 4.1% | — | Varnish-cache VarnishVarnish Cache Project Varnish CacheDebian Linux | 16/11/2017 | 17/6/2026 | vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a VFP_GetStorage buffer is larger than intended in certain circumstances involving -sfile Stevedore transient objects. | |
| Modificada | Alta (7.5) | 2.4% | — | Varnish-cache VarnishVarnish Cache Project Varnish CacheVarnish-software Varnish Cache | 4/8/2017 | 17/6/2026 | An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2. A wrong if statement in the varnishd source code means that particular invalid requests from the client can trigger an assert, related to an Integer Overflow. This causes the varnishd worker process… | |
| Modificada | Alta (7.5) | 3.5% | — | Varnish Cache Project Varnish CacheDebian Linux | 25/4/2016 | 17/6/2026 | Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request. | |
| Modificada | Baja (2.1) | 0.37% | — | Varnish Cache Project Varnish Cache | 8/5/2014 | 16/6/2026 | varnish 3.0.3 uses world-readable permissions for the /var/log/varnish/ directory and the log files in the directory, which allows local users to obtain sensitive information by reading the files. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 3.2% | — | Varnish-cache VarnishVarnish Cache Project Varnish Cache | 1/11/2013 | 16/6/2026 | Varnish before 3.0.5 allows remote attackers to cause a denial of service (child-process crash and temporary caching outage) via a GET request with trailing whitespace characters and no URI. | |
| Modificada | Media (4.3) | 1.3% | — | Varnish Http Accelerator Integration Project Varnish | 27/3/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Varnish module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta2 for Drupal allow remote attackers to inject arbitrary web script or HTML via crafted a (1) Watchdog message or (2) admin setting. | |
| Modificada | Alta (7.5) | 64% | 💥 Exploit | Varnish.projects.linpro Varnish | 5/4/2010 | 16/6/2026 | The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy server in Varnish before 2.1.0 does not require authentication for commands received through a TCP port, which allows remote attackers to (1) execute arbitrary code via a vcl.inline directive that… | |
| Modificada | Crítica (9.8) | 13% | 💥 Exploit | Varnish.projects.linpro Varnish | 13/1/2010 | 16/6/2026 | Varnish 2.0.6 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. NOTE: the vendor disputes the… |