Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
115 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.9) | 0.38% | — | Cloudflare Vite PluginAI | 19/9/2025 | 17/6/2026 | The Cloudflare Vite plugin enables a full-featured integration between Vite and the Workers runtime. When utilising the Cloudflare Vite plugin in its default configuration, all files are exposed by the local dev server, including files in the root directory that contain secret information such as .env and .dev.vars.… | |
| Analizada | Media (6.5) | 0.83% | 💥 Exploit | @astrojs/cloudflare | 5/9/2025 | 17/6/2026 | Astro is a web framework for content-driven websites. Versions 11.0.3 through 12.6.5 are vulnerable to SSRF when using Astro's Cloudflare adapter. When configured with output: 'server' while using the default imageService: 'compile', the generated image optimization endpoint doesn't check the URLs it receives,… | |
| Aplazada | Crítica (9.8) | 18% | 💥 PoC | Cloudflare Image ResizingAI | 19/8/2025 | 17/6/2026 | The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication and insufficient sanitization within its hook_rest_pre_dispatch() method in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to inject arbitrary PHP into… | |
| Aplazada | Media (5.3) | 0.39% | — | OAKAIDenoAIDeno DeployAINodejsAI+2 | 9/8/2025 | 17/6/2026 | oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. In versions 17.1.5 and below, it's possible to significantly slow down an oak server with specially crafted values of the x-forwarded-proto or x-forwarded-for headers. | |
| Analizada | Alta (8.7) | 0.40% | — | Cloudflare Quiche | 7/8/2025 | 17/6/2026 | Cloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000 https://datatracker.ietf.org/doc/html/rfc9000#section-5.1 . Once the QUIC handshake completes, a… | |
| Analizada | Alta (7.5) | 0.94% | — | Cloudflare Quiche | 18/6/2025 | 17/6/2026 | Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster than the path might actually support. An unauthenticated remote attacker can exploit the vulnerability by first completing a handshake and initiating a… | |
| Analizada | Media (5.3) | 0.86% | — | Cloudflare Quiche | 18/6/2025 | 17/6/2026 | Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster than the path might actually support. An unauthenticated remote attacker can exploit the vulnerability by first completing a handshake and initiating a… | |
| Analizada | Alta (7.8) | 0.97% | — | Create-cloudflareOpennextjs Opennext FOR Cloudflare | 16/6/2025 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package. The vulnerability stems from an unimplemented feature in the Cloudflare adapter for Open Next, which allowed unauthenticated users to proxy arbitrary remote content via the /_next/image endpoint. This issue allowed… | |
| Analizada | Alta (7.4) | 0.50% | — | Cloudflare Pingora | 22/5/2025 | 17/6/2026 | A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP requests to be injected via manipulated request bodies on cache HITs, leading to unauthorized request execution and potential cache poisoning. Fixed in:… | |
| Analizada | Media (5.3) | 0.57% | — | Cloudflare Workers-oauth-provider | 1/5/2025 | 17/6/2026 | PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp . However, it was found that an attacker could cause the check to be skipped. Fixed in: https://github.com/cloudflare/workers-oauth-provider/pull/27… | |
| Analizada | Media (6) | 0.32% | — | Cloudflare Workers-oauth-provider | 1/5/2025 | 17/6/2026 | The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp , did not correctly validate that redirect_uri was on the allowed list of redirect URIs for the given client registration. Fixed in: https://github.com/cloudflare/workers-oauth-provider/pull/26… | |
| Aplazada | Alta (7.1) | 0.28% | — | Shanaver Cloudflare-cache-purgeAI | 31/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanaver CloudFlare(R) Cache Purge cloudflare-cache-purge allows Reflected XSS.This issue affects CloudFlare(R) Cache Purge: from n/a through <= 1.2. | |
| Analizada | Media (5.5) | 0.14% | — | Cloudflare Octorpki | 29/1/2025 | 17/6/2026 | When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set as root. Since the provided service definition defaults to root ( https://github.com/cloudflare/cfrpki/blob/master/package/octorpki.service ) this could allow for a vector, when combined with another… | |
| Analizada | Media (6.1) | 0.30% | — | Cloudflare Warp | 22/1/2025 | 17/6/2026 | Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation. User with a low system privileges can create a set of symlinks inside the C:\ProgramData\Cloudflare\warp-diag-partials folder. After triggering the 'Reset all settings" option the WARP service will delete the files that… | |
| Analizada | Alta (7.5) | 1.2% | — | Cloudflare Quiche | 12/3/2024 | 17/6/2026 | Cloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO… | |
| Analizada | Media (5.3) | 0.66% | — | Cloudflare Quiche | 12/3/2024 | 17/6/2026 | Cloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1… | |
| Modificada | Media (6.5) | 0.80% | — | Cloudflare | 29/1/2024 | 17/6/2026 | The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged account to access data from the Cloudflare API. | |
| Modificada | Media (5.5) | 0.24% | — | Cloudflare Zlib | 4/1/2024 | 17/6/2026 | Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c). The issues resulted from improper input validation and heap-based buffer overflow. A local attacker could exploit the problem during compression using a crafted… | |
| Modificada | Alta (8) | 0.63% | — | Cloudflare Wrangler | 29/12/2023 | 17/6/2026 | The V8 inspector intentionally allows arbitrary code execution within the Workers sandbox for debugging. wrangler dev would previously start an inspector server listening on all network interfaces. This would allow an attacker on the local network to connect to the inspector and run arbitrary code. Additionally, the… | |
| Modificada | Media (5.7) | 0.70% | — | Cloudflare Wrangler | 29/12/2023 | 17/6/2026 | Sending specially crafted HTTP requests and inspector messages to Wrangler's dev server could result in any file on the user's computer being accessible over the local network. An attacker that could trick any user on the local network into opening a malicious website could also read any file. | |
| Modificada | Alta (8.1) | 0.55% | — | Cloudflare Miniflare | 29/12/2023 | 17/6/2026 | Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Miniflare was configured to listen on external network interfaces (as was the default in wrangler until 3.19.0), an attacker on the local network could access other local… | |
| Modificada | Media (5.3) | 0.76% | — | Cloudflare Quiche | 12/12/2023 | 17/6/2026 | quiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which could lead to excessive resource consumption. QUIC path validation (RFC 9000 Section 8.2) requires that the recipient of a PATH_CHALLENGE frame responds by sending a PATH_RESPONSE. An unauthenticated… | |
| Modificada | Media (5.3) | 0.62% | — | Cloudflare Boring | 5/12/2023 | 17/6/2026 | The tokio-boring library in version 4.0.0 is affected by a memory leak issue that can lead to excessive resource consumption and potential DoS by resource exhaustion. The set_ex_data function used by the library did not deallocate memory used by pre-existing data in memory each time after completing a TLS connection… | |
| Modificada | Media (5.5) | 0.20% | — | Cloudflare Warp | 7/9/2023 | 17/6/2026 | Zero Trust Administrators have the ability to disallow end users from disabling WARP on their devices. Override codes can also be created by the Administrators to allow a device to temporarily be disconnected from WARP, however, due to lack of server side validation, an attacker with local access to the device, could… | |
| Modificada | Baja (3.7) | 0.22% | — | Cloudflare Warp | 29/8/2023 | 17/6/2026 | Due to a misconfiguration, the WARP Mobile Client (< 6.29) for Android was susceptible to a tapjacking attack. In the event that an attacker built a malicious application and managed to install it on a victim's device, the attacker would be able to trick the user into believing that the app shown on the screen was the… |