Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
458 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.29% | — | Aruba Hispeed CacheAI | 19/2/2026 | 17/6/2026 | The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the dbstatus parameter in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Alta (7.2) | 0.20% | — | Optimole Super Page CacheAI | 14/2/2026 | 17/6/2026 | The Super Page Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Activity Log in all versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Crítica (9.8) | 0.54% | — | Python-diskcache DiskcacheAI | 11/2/2026 | 15/7/2026 | DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim application reads from the cache. | |
| Aplazada | Media (5.3) | 0.39% | — | Cloudpanel CLP Varnish CacheAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in CloudPanel CLP Varnish Cache clp-varnish-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CLP Varnish Cache: from n/a through <= 1.0.2. | |
| Aplazada | Media (4.3) | 0.30% | — | Nawawi Jamili Docket CacheAI | 8/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Nawawi Jamili Docket Cache docket-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Docket Cache: from n/a through <= 24.07.04. | |
| Aplazada | Media (6.5) | 0.29% | — | Aruba Hispeed CacheAI | 8/1/2026 | 5/10/2026 | Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Aruba HiSpeed Cache: from n/a through < 3.0.3. | |
| Analizada | Baja (2) | 0.24% | — | Sohu Cachecloud | 30/12/2025 | 5/10/2026 | A flaw has been found in SohuTV CacheCloud up to 3.2.0. This vulnerability affects the function index of the file src/main/java/com/sohu/cache/web/controller/AppDataMigrateController.java. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been published and… | |
| Analizada | Baja (2.1) | 0.33% | — | Sohu Cachecloud | 30/12/2025 | 5/10/2026 | A vulnerability was detected in SohuTV CacheCloud up to 3.2.0. This affects the function init of the file src/main/java/com/sohu/cache/web/controller/LoginController.java. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used. The project was… | |
| Analizada | Baja (2) | 0.25% | — | Sohu Cachecloud | 30/12/2025 | 30/9/2026 | A security vulnerability has been detected in SohuTV CacheCloud up to 3.2.0. Affected by this issue is the function doMachineList/doPodList of the file src/main/java/com/sohu/cache/web/controller/MachineManageController.java. The manipulation leads to cross site scripting. The attack may be initiated remotely. The… | |
| Analizada | Baja (1.9) | 0.25% | — | Sohu Cachecloud | 29/12/2025 | 1/10/2026 | A vulnerability was determined in SohuTV CacheCloud up to 3.2.0. Affected is the function doQuartzList of the file src/main/java/com/sohu/cache/web/controller/QuartzManageController.java. Executing manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Baja (2) | 0.24% | — | Sohu Cachecloud | 29/12/2025 | 17/6/2026 | A flaw has been found in SohuTV CacheCloud up to 3.2.0. The impacted element is the function redirectNoPower of the file src/main/java/com/sohu/cache/web/controller/WebResourceController.java. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been… | |
| Analizada | Baja (1.9) | 0.30% | — | Sohu Cachecloud | 29/12/2025 | 17/6/2026 | A vulnerability was detected in SohuTV CacheCloud up to 3.2.0. The affected element is the function getExceptionStatisticsByClient/getCommandStatisticsByClient/doIndex of the file src/main/java/com/sohu/cache/web/controller/AppClientDataShowController.java. The manipulation results in cross site scripting. The attack… | |
| Analizada | Media (6) | 0.32% | — | Axios-cache-interceptor Axios Cache Interceptor | 29/12/2025 | 1/10/2026 | Axios Cache Interceptor is a cache interceptor for axios. Prior to version 1.11.1, when a server calls an upstream service using different auth tokens, axios-cache-interceptor returns incorrect cached responses, leading to authorization bypass. The cache key is generated only from the URL, ignoring request headers… | |
| Analizada | Baja (1.9) | 0.25% | — | Sohu Cachecloud | 29/12/2025 | 1/10/2026 | A vulnerability was found in SohuTV CacheCloud up to 3.2.0. This impacts the function index of the file src/main/java/com/sohu/cache/web/controller/ResourceController.java. Performing manipulation results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and… | |
| Analizada | Baja (1.9) | 0.25% | — | Sohu Cachecloud | 29/12/2025 | 30/9/2026 | A vulnerability has been found in SohuTV CacheCloud up to 3.2.0. This affects the function taskQueueList of the file src/main/java/com/sohu/cache/web/controller/TaskController.java. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public… | |
| Analizada | Baja (2) | 0.24% | — | Sohu Cachecloud | 29/12/2025 | 17/6/2026 | A weakness has been identified in SohuTV CacheCloud up to 3.2.0. Affected is the function advancedAnalysis of the file src/main/java/com/sohu/cache/web/controller/InstanceController.java. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made… | |
| Analizada | Baja (2) | 0.24% | — | Sohu Cachecloud | 29/12/2025 | 17/6/2026 | A security flaw has been discovered in SohuTV CacheCloud up to 3.2.0. This impacts the function preview of the file src/main/java/com/sohu/cache/web/controller/RedisConfigTemplateController.java. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit has been released to the… | |
| Analizada | Baja (2) | 0.24% | — | Sohu Cachecloud | 29/12/2025 | 17/6/2026 | A vulnerability was identified in SohuTV CacheCloud up to 3.2.0. This affects the function index of the file src/main/java/com/sohu/cache/web/controller/ServerController.java. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be… | |
| Analizada | Baja (2) | 0.27% | — | Sohu Cachecloud | 29/12/2025 | 5/10/2026 | A vulnerability was detected in SohuTV CacheCloud up to 3.2.0. Affected by this issue is the function doAppList/appCommandAnalysis of the file src/main/java/com/sohu/cache/web/controller/AppController.java. Performing manipulation results in cross site scripting. It is possible to initiate the attack remotely. The… | |
| Analizada | Baja (2) | 0.24% | — | Sohu Cachecloud | 29/12/2025 | 5/10/2026 | A security vulnerability has been detected in SohuTV CacheCloud up to 3.2.0. Affected by this vulnerability is the function doAppAuditList of the file src/main/java/com/sohu/cache/web/controller/AppManageController.java. Such manipulation leads to cross site scripting. The attack may be performed from remote. The… | |
| Analizada | Baja (1.9) | 0.24% | — | Sohu Cachecloud | 28/12/2025 | 6/10/2026 | A vulnerability was detected in SohuTV CacheCloud up to 3.2.0. This impacts the function doUserList of the file src/main/java/com/sohu/cache/web/controller/UserManageController.java. Performing manipulation results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be… | |
| Analizada | Baja (1.9) | 0.24% | — | Sohu Cachecloud | 28/12/2025 | 6/10/2026 | A security vulnerability has been detected in SohuTV CacheCloud up to 3.2.0. This affects the function doTotalList of the file src/main/java/com/sohu/cache/web/controller/TotalManageController.java. Such manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed… | |
| Aplazada | Alta (8.1) | 0.48% | — | Nawawi Jamili Docket CacheAIPHPAI | 24/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nawawi Jamili Docket Cache docket-cache allows PHP Local File Inclusion.This issue affects Docket Cache: from n/a through <= 24.07.03. | |
| Aplazada | Baja (3.5) | 0.24% | — | Wpfastestcache WP Fastest Cache PremiumAI | 12/12/2025 | 17/6/2026 | The WP Fastest Cache Premium plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.7.4 via the 'get_server_time_ajax_request' AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary… | |
| Aplazada | Media (4.3) | 0.13% | — | Taylor Hawkes WP Fast CacheAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Taylor Hawkes WP Fast Cache allows Cross Site Request Forgery.This issue affects WP Fast Cache: from n/a through 1.5. |