Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
458 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.65% | — | Cloudfoundry Cf-auth-proxyAICloudfoundry Log-cache ReleaseAI | 1/6/2026 | 22/7/2026 | Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to every log and metric for every application and platform component via minting a JWT that the cf-auth-proxy accepts as a valid logs.admin token. Affected versions: -… | |
| Pendiente de análisis | Alta (7.8) | 0.18% | — | Rrdtool RrdcachedAI | 1/6/2026 | 28/9/2026 | A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a stack-based buffer overflow by sending an oversized CREATE request. This vulnerability can lead to a denial of service by crashing the daemon or potentially allow for arbitrary code execution,… | |
| Aplazada | Baja (2.1) | 0.28% | — | Westboy CicadascmsAISpringframework CacheAI | 30/5/2026 | 22/7/2026 | A flaw has been found in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. Impacted is the function Search of the file org/springframework/cache/support/AbstractCacheManager.java. This manipulation of the argument s causes cross site scripting. Remote exploitation of the attack is possible. The… | |
| Analizada | Alta (8.6) | 0.21% | — | Cnighswonger Claude-code-cache-fix | 27/5/2026 | 17/6/2026 | claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2, tools/quota-statusline.sh (introduced in v3.5.0) interpolates Claude Code's hook stdin payload directly into a Python triple-quoted string literal. A ''' byte sequence in any user-controlled field of the payload closes the… | |
| Aplazada | Alta (7.2) | 0.44% | — | Litespeedtech Litespeed CacheAI | 27/5/2026 | 17/6/2026 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1/notify_ccss and /wp-json/litespeed/v1/notify_ucss REST API endpoints in all versions up to, and including, 7.7. These endpoints accept CSS content from QUIC.cloud callback notifications and store it to… | |
| Analizada | Crítica (9.3) | 2.1% | ⚠ Explotación activa | Mirasvit Full Page Cache Warmer | 26/5/2026 | 24/7/2026 | Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native… | |
| Analizada | Alta (8.1) | 0.55% | — | Memcached | 20/5/2026 | 24/7/2026 | In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass. | |
| Modificada | Alta (8.1) | 1.3% | — | Memcached | 20/5/2026 | 18/9/2026 | In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass. | |
| Aplazada | Alta (8.8) | 0.45% | — | AutoptimizeAIClearfy CacheAISiteground Speed OptimizerAI | 18/5/2026 | 17/6/2026 | The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular… | |
| Analizada | Crítica (9.3) | 1.0% | — | Kvcache-ai Ktransformers | 23/4/2026 | 14/7/2026 | KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authentication and deserializes incoming messages using pickle.loads() without validation. Attackers can send a crafted… | |
| Aplazada | Crítica (9.8) | 3.8% | — | Breeze CacheAI | 23/4/2026 | 17/6/2026 | The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which… | |
| Analizada | Alta (7.5) | 0.45% | — | Vinyl-cache Vinyl Cache | 12/4/2026 | 17/6/2026 | Varnish Cache 9 before 9.0.1 allows a "workspace overflow" denial of service (daemon panic) after timeout_linger. A malicious client could send an HTTP/1 request, wait long enough until the session releases its worker thread (timeout_linger) and resume traffic before the session is closed (timeout_idle) sending more… | |
| Analizada | Alta (7.5) | 0.40% | — | Varnish-software Varnish EnterpriseVinyl-cache Vinyl Cache | 12/4/2026 | 17/6/2026 | Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for certain amounts of prefetched data. The setup of an HTTP/2 session starts with a speculative HTTP/1 transport, and upon upgrading to h2 the HTTP/1 request is repurposed as stream… | |
| Aplazada | Media (4.3) | 0.18% | — | Aruba Hispeed CacheAI | 10/4/2026 | 17/6/2026 | The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.4. This is due to missing nonce verification on the `ahsc_ajax_reset_options()` function. This makes it possible for unauthenticated attackers to reset all plugin settings to their default… | |
| Aplazada | Alta (7.5) | 2.7% | — | Boldgrid W3 Total CacheAI | 2/4/2026 | 17/6/2026 | The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.3. This is due to the plugin bypassing its entire output buffering and processing pipeline when the request's User-Agent header contains "W3 Total Cache", which causes raw mfunc/mclude dynamic… | |
| Analizada | Crítica (9.8) | 0.37% | — | Varnish-software Varnish EnterpriseVinyl-cache Vinyl Cache | 27/3/2026 | 17/6/2026 | Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass. | |
| Modificada | Crítica (9.2) | 13% | — | Squid-cache Squid | 26/3/2026 | 15/7/2026 | Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is… | |
| Analizada | Media (6.9) | 2.2% | — | Squid-cache Squid | 26/3/2026 | 17/6/2026 | Squid is a caching proxy for the Web. Prior to version 7.5, due to improper input validation, Squid is vulnerable to out of bounds read when handling ICP traffic. This problem allows a remote attacker to receive small amounts of memory potentially containing sensitive information when responding with errors to invalid… | |
| Modificada | Alta (8.7) | 10.0% | — | Squid-cache Squid | 26/3/2026 | 15/7/2026 | Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack… | |
| Aplazada | Alta (7.1) | 0.18% | — | Acato WP Rest CacheAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Acato WP REST Cache wp-rest-cache allows Stored XSS.This issue affects WP REST Cache: from n/a through <= 2026.1.0. | |
| Aplazada | Crítica (9) | 0.45% | — | Boldgrid W3 Total CacheAI | 5/3/2026 | 17/6/2026 | Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects W3 Total Cache: from n/a through <= 2.9.1. | |
| Aplazada | Media (5.1) | 0.23% | — | Aruba Hispeed CacheAI | 23/2/2026 | 17/6/2026 | Aruba HiSpeed Cache (aruba-hispeed-cache) WordPress plugin versions prior to 3.0.5 contain a cross-site request forgery (CSRF) vulnerability affecting multiple administrative AJAX actions. The handlers for ahsc_reset_options, ahsc_debug_status, and ahsc_enable_purge perform authentication and capability checks but do… | |
| Aplazada | Media (6.5) | 0.25% | — | Litespeed Technologies Litespeed CacheAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through <= 6.5.2. | |
| Aplazada | Media (6.5) | 0.20% | — | Aruba Hispeed CacheAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Aruba HiSpeed Cache: from n/a through <= 3.0.4. | |
| Aplazada | Media (6.5) | 0.29% | — | Aruba Hispeed CacheAI | 19/2/2026 | 17/6/2026 | The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the multiple functions in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to modify plugin's configuration settings, enable or disable… |