Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
458 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.29% | — | Ergonet CacheAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in ergonet Ergonet Cache ergonet-varnish-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ergonet Cache: from n/a through <= 1.0.13. | |
| Aplazada | Media (4.3) | 0.22% | — | Wpfastestcache WP Fastest CacheAI | 27/11/2025 | 17/6/2026 | The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpfc_db_fix_callback() function in all versions up to, and including, 1.4.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to initiate… | |
| Aplazada | Crítica (9) | 23% | — | Boldgrid W3 Total CacheAI | 17/11/2025 | 17/6/2026 | The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post. | |
| Aplazada | Media (6.1) | 0.38% | — | Litespeedtech Litespeed CacheAI | 29/10/2025 | 17/6/2026 | The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 7.5.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they… | |
| Aplazada | Media (5.4) | 0.22% | — | Apiki GocacheAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Apiki GoCache gocache-cdn allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GoCache: from n/a through <= 1.3.6. | |
| Aplazada | Media (4.3) | 0.20% | — | Nginxcacheoptimizer Nginx Cache OptimizerAI | 24/10/2025 | 17/6/2026 | The NGINX Cache Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nginxcacheoptimizer-blacklist-update' AJAX action in all versions up to, and including, 1.1. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Modificada | Alta (7.5) | 63% | — | Squid-cache Squid | 17/10/2025 | 17/6/2026 | Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows information disclosure. The vulnerability allows a script to bypass browser security protections and learn the credentials a trusted client uses to authenticate. This… | |
| Analizada | Alta (8.7) | 0.66% | — | Microsoft Azure Cache FOR RedisMicrosoft Azure Managed Redis | 9/10/2025 | 17/6/2026 | Redis Enterprise Elevation of Privilege Vulnerability | |
| Analizada | Media (5.1) | 0.18% | — | Apt-cacher-ng Project Apt-cacher-ng | 29/9/2025 | 17/6/2026 | Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows malicious scripts (XSS) to be executed in “/html/<filename>.html”. | |
| Analizada | Media (5.1) | 0.18% | — | Apt-cacher-ng Project Apt-cacher-ng | 29/9/2025 | 17/6/2026 | Reflected Cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows an attacker to execute malicious scripts (XSS) in the web management application. The vulnerability is caused by improper handling of GET inputs included in the URL in “/acng-report.html”. | |
| Analizada | Media (4) | 0.41% | — | Squid-cache Squid | 26/9/2025 | 17/6/2026 | Squid through 7.1 mishandles ASN.1 encoding of long SNMP OIDs. This occurs in asn_build_objid in lib/snmplib/asn1.c. | |
| Aplazada | Crítica (9.3) | 1.7% | — | Intersystems CacheAI | 16/9/2025 | 1/10/2026 | A stack-based buffer overflow exists in the UtilConfigHome.csp endpoint of InterSystems Caché 2009.1. The vulnerability is triggered by sending a specially crafted HTTP GET request containing an oversized argument to the .csp handler. Due to insufficient bounds checking, the input overflows a stack buffer, allowing an… | |
| Aplazada | Media (6.4) | 0.26% | — | Litespeed Technologies Litespeed CacheAI | 9/9/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 7.0.1. | |
| Aplazada | Alta (7.1) | 0.13% | — | Dsingh Purge Varnish CacheAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dsingh Purge Varnish Cache purge-varnish allows Stored XSS.This issue affects Purge Varnish Cache: from n/a through <= 2.6. | |
| Aplazada | Media (4.3) | 0.25% | — | LwscacheAI | 29/8/2025 | 17/6/2026 | The LWSCache plugin for WordPress is vulnerable to unauthorized modification of data due to improper authorization on the lwscache_activatePlugin() function in all versions up to, and including, 2.8.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate arbitrary… | |
| Aplazada | Alta (7.5) | 0.56% | — | Acato WP Rest CacheAI | 14/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Acato WP REST Cache wp-rest-cache allows PHP Local File Inclusion.This issue affects WP REST Cache: from n/a through <= 2025.1.0. | |
| Analizada | Crítica (9.8) | 0.81% | — | Codefuse Modelcache | 11/8/2025 | 17/6/2026 | ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnerability allows attackers to execute arbitrary code via supplying crafted data. | |
| Modificada | Crítica (9.8) | 24% | — | Squid-cache Squid | 1/8/2025 | 17/6/2026 | Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to incorrect buffer management. This has been fixed in version 6.4. To work around this issue, disable URN access permissions. | |
| Aplazada | Alta (7.2) | 0.68% | — | Nginx Cache Purge PreloadAI | 22/7/2025 | 17/6/2026 | The Nginx Cache Purge Preload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.1 via the 'nppp_preload_cache_on_update' function. This is due to insufficient sanitization of the $_SERVER['HTTP_REFERERER'] parameter passed from the… | |
| Aplazada | Alta (8.6) | 0.41% | — | Jose Mortellaro Content NO CacheAI | 27/6/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Jose Mortellaro Content No Cache content-no-cache allows Code Injection.This issue affects Content No Cache: from n/a through <= 0.1.4. | |
| Analizada | Media (4.8) | 0.31% | — | Pixeljar Geocache Stat BAR Widget | 15/5/2025 | 17/6/2026 | The Geocache Stat Bar Widget WordPress plugin through 0.911 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (5.4) | 0.36% | — | Varnish CacheAIVarnish-software Varnish EnterpriseAI | 13/5/2025 | 17/6/2026 | Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries. | |
| Aplazada | Alta (7.5) | 0.70% | — | Nawawi Jamili Docket CacheAIPHPAI | 17/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nawawi Jamili Docket Cache docket-cache allows PHP Local File Inclusion.This issue affects Docket Cache: from n/a through <= 24.07.02. | |
| Aplazada | Media (5.9) | 0.37% | — | Cache-control-by-cacholongAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Preliot Cache control by Cacholong cache-control-by-cacholong allows Stored XSS.This issue affects Cache control by Cacholong: from n/a through <= 5.4.1. | |
| Aplazada | Media (4.3) | 0.21% | — | Cache Control BY CacholongAI | 1/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Preliot Cache control by Cacholong cache-control-by-cacholong allows Cross Site Request Forgery.This issue affects Cache control by Cacholong: from n/a through <= 5.4.1. |