Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
458 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.22% | — | Cache Utility Project Cache Utility | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Cache Utility allows Cross Site Request Forgery.This issue affects Cache Utility: from 0.0.0 before 1.2.1. | |
| Aplazada | Media (5.3) | 0.30% | — | Webrangers Clear Sucuri CacheAI | 28/3/2025 | 17/6/2026 | Missing Authorization vulnerability in webrangers Clear Sucuri Cache clear-sucuri-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clear Sucuri Cache: from n/a through <= 1.4. | |
| Aplazada | Media (4.3) | 0.20% | — | Hitoy Super Static CacheAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in hitoy Super Static Cache super-static-cache allows Cross Site Request Forgery.This issue affects Super Static Cache: from n/a through <= 3.3.5. | |
| Modificada | Media (4.8) | 0.31% | — | Varnish-software Varnish EnterpriseVarnish Cache Project Varnish Cache | 21/3/2025 | 17/6/2026 | Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests. | |
| Analizada | Alta (7.2) | 0.36% | — | Megaoptim Rapid Cache | 18/2/2025 | 17/6/2026 | The Rapid Cache plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 1.2.3. This is due to plugin storing HTTP headers in the cached data. This makes it possible for unauthenticated attackers to poison the cache with custom HTTP headers that may be unsanitized which can lead to… | |
| Aplazada | Alta (7.1) | 0.28% | — | Shanaver Cloudflare-cache-purgeAI | 31/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanaver CloudFlare(R) Cache Purge cloudflare-cache-purge allows Reflected XSS.This issue affects CloudFlare(R) Cache Purge: from n/a through <= 1.2. | |
| Aplazada | Alta (7.1) | 0.39% | — | Webhue Wh-cache-and-securityAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webhue WH Cache & Security wh-cache-and-security allows Reflected XSS.This issue affects WH Cache & Security: from n/a through <= 1.1.2. | |
| Aplazada | Alta (7.1) | 0.20% | — | Cybio GravatarlocalcacheAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in cybio GravatarLocalCache gravatarlocalcache allows Cross Site Request Forgery.This issue affects GravatarLocalCache: from n/a through <= 1.1.2. | |
| Aplazada | Media (4.3) | 0.41% | — | Ekaterir Cache Sniper FOR NginxAI | 16/1/2025 | 17/6/2026 | Missing Authorization vulnerability in ekaterir Cache Sniper for Nginx snipe-nginx-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cache Sniper for Nginx: from n/a through <= 1.0.4.2. | |
| Analizada | Alta (8.5) | 1.8% | 💥 PoC | Boldgrid W3 Total Cache | 14/1/2025 | 17/6/2026 | The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page function in all versions up to, and including, 2.8.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain the plugin's nonce… | |
| Analizada | Alta (7.5) | 2.3% | 💥 Exploit | Boldgrid W3 Total Cache | 14/1/2025 | 17/6/2026 | The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it possible for unauthenticated attackers to view potentially sensitive information in the exposed log file. For example, the log file may… | |
| Analizada | Media (5.3) | 0.51% | — | Boldgrid W3 Total Cache | 14/1/2025 | 17/6/2026 | The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to deactivate the plugin as well as activate and deactivate plugin… | |
| Aplazada | Media (4.3) | 0.35% | — | Juni Hestia Nginx CacheAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Juni Hestia Nginx Cache hestia-nginx-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hestia Nginx Cache: from n/a through <= 2.4.0. | |
| Aplazada | Media (5.3) | 0.40% | — | Content NO CacheAI | 24/12/2024 | 17/6/2026 | The Content No Cache: prevent specific content from being cached plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 0.1.2 via the eos_dyn_get_content action due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated… | |
| Aplazada | Media (4.4) | 0.39% | — | Bodi0 Easy CacheAI | 14/12/2024 | 17/6/2026 | The bodi0`s Easy cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cache-folder' parameter in all versions up to, and including, 0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and… | |
| Analizada | Alta (7.8) | 0.36% | 💥 PoC | Mozilla Sccache | 26/11/2024 | 17/6/2026 | On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the code in a shared library passed to LD_PRELOAD. If the server is run as root (which is the default when installing the snap package https://snapcraft.io/sccache ), this means a user running the… | |
| Analizada | Media (5.3) | 0.33% | — | Opensuse Mirrorcache | 13/11/2024 | 17/6/2026 | A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in openSUSE Tumbleweed MirrorCache allows the execution of arbitrary JS via reflected XSS in the REGEX and P parameters. This issue affects MirrorCache before 1.083. | |
| Aplazada | Media (5.4) | 0.32% | — | Creative Motion Clearfy CacheAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Creative Motion Clearfy Cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clearfy Cache: from n/a through 2.2.4. | |
| Aplazada | Media (4.3) | 0.49% | — | Aruba Hispeed CacheAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Aruba.It Aruba HiSpeed Cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Aruba HiSpeed Cache: from n/a through 2.0.12. | |
| Modificada | Crítica (9.8) | 0.90% | — | Litespeedtech Litespeed Cache | 29/10/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from n/a through <= 6.5.1. | |
| Modificada | Alta (7.5) | 48% | — | Squid-cache Squid | 28/10/2024 | 17/6/2026 | Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to Input Validation, Premature Release of Resource During Expected Lifetime, and Missing Release of Resource after Effective Lifetime bugs, Squid is vulnerable to Denial of Service attacks by a trusted server against all… | |
| Modificada | Crítica (9.8) | 82% | 💥 Exploit | Litespeedtech Litespeed Cache | 20/10/2024 | 17/6/2026 | Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a through < 6.5.0.1. | |
| Modificada | Alta (8.8) | 0.65% | — | Litespeedtech Litespeed Cache | 16/10/2024 | 17/6/2026 | Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through <= 6.4.1. | |
| Modificada | Alta (8.1) | 1.5% | 💥 Exploit | Wpfastestcache WP Fastest Cache | 16/10/2024 | 17/6/2026 | The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a lack of capability checking and insufficient path validation. This makes it possible for authenticated users with minimal permissions to delete arbitrary files from the… | |
| Modificada | Media (6.1) | 1.4% | 💥 Exploit | Litespeedtech Litespeed Cache | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through <= 6.5.0.2. |