Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
458 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.26% | — | Litespeedtech Litespeed Cache | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through <= 6.5.0.2. | |
| Analizada | Media (4.8) | 0.28% | — | Litespeedtech Litespeed Cache | 25/9/2024 | 17/6/2026 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all versions up to, and including, 6.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… | |
| Analizada | Alta (7.5) | 0.81% | 💥 PoC | Boldgrid W3 Total Cache | 25/9/2024 | 17/6/2026 | The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visible plugin source. This can allow unauthenticated attackers to impersonate W3 Total Cache and gain access to user account… | |
| Modificada | Media (5.4) | 0.18% | — | Softaculous Speedycache | 26/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Softaculous SpeedyCache speedycache.This issue affects SpeedyCache: from n/a through <= 1.1.8. | |
| Modificada | Crítica (9.8) | 68% | 💥 Exploit | Litespeedtech Litespeed Cache | 21/8/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1. | |
| Modificada | Media (5.4) | 0.18% | — | Litespeedtech Litespeed Cache | 24/7/2024 | 17/6/2026 | The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0.1. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to update the token setting and inject malicious JavaScript via a forged request… | |
| Modificada | Media (6.3) | 6.3% | — | Squid-cache Squid | 25/6/2024 | 17/6/2026 | Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Out-of-bounds Write error when assigning ESI variables, Squid is susceptible to a Memory Corruption error. This error can lead to a Denial of Service attack. | |
| Aplazada | Alta (7.2) | 0.94% | — | Wpfastestcache WP Fastest CacheAI | 23/5/2024 | 17/6/2026 | The WP Fastest Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.6 via the specificDeleteCache function. This makes it possible for authenticated attackers to delete arbitrary files on the server, which can include wp-config.php files of the affected site or… | |
| Aplazada | Media (4.3) | 0.19% | — | Creative Motion Clearfy CacheAI | 17/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Creative Motion Clearfy Cache.This issue affects Clearfy Cache: from n/a through 2.2.1. | |
| Modificada | Media (5.3) | 0.41% | — | Litespeedtech Litespeed Cache | 16/4/2024 | 17/6/2026 | Missing Authorization vulnerability in LiteSpeed Technologies LiteSpeed Cache.This issue affects LiteSpeed Cache: from n/a through 5.7. | |
| Modificada | Media (6.1) | 55% | 💥 Exploit | Litespeedtech Litespeed Cache | 16/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 5.7. | |
| Aplazada | Alta (7.5) | 3.7% | — | Varnish CacheAIVarnish EnterpriseAI | 24/3/2024 | 17/6/2026 | Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, allows credits exhaustion for an HTTP/2 connection control flow window, aka a Broke Window Attack. | |
| Modificada | Media (6.1) | 0.19% | — | Optimole Super Page Cache | 21/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Optimole Super Page Cache for Cloudflare allows Stored XSS.This issue affects Super Page Cache for Cloudflare: from n/a through 4.7.5. | |
| Aplazada | Crítica (9.1) | 0.32% | — | Rocket.chat AuditAIFilecachetoolsAI | 18/3/2024 | 17/6/2026 | Rocket.Chat.Audit through 5ad78e8 depends on filecachetools, which does not exist in PyPI. | |
| Modificada | Alta (7.5) | 65% | — | Squid-cache SquidFedoraproject FedoraNetapp Bluexp | 6/3/2024 | 17/6/2026 | Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack against HTTP Chunked decoder due to an uncontrolled recursion bug. This problem allows a remote attacker to cause Denial of Service when sending a crafted, chunked, encoded HTTP… | |
| Analizada | Alta (7.5) | 88% | — | Squid-cache SquidNetapp Bluexp | 14/2/2024 | 17/6/2026 | Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into Unsafe Value bug ,Squid may be vulnerable to a Denial of Service attack against HTTP header parsing. This problem allows a remote client or a remote server to perform Denial of Service when sending… | |
| Modificada | Media (6.5) | 60% | — | Squid-cache Squid | 24/1/2024 | 17/6/2026 | Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid… | |
| Modificada | Media (6.1) | 0.25% | — | Wpfastestcache WP Fastest Cache | 16/1/2024 | 17/6/2026 | The WP Fastest Cache WordPress plugin before 0.9.5 is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action, and does not sanitise and escape some the options available via the action, which could allow attackers to make logged in high privilege users call it and set a Cross-Site Scripting payload | |
| Modificada | Alta (8.8) | 1.2% | — | Wpfastestcache WP Fastest Cache | 16/1/2024 | 17/6/2026 | The WP Fastest Cache WordPress plugin before 0.9.5 does not escape user input in the set_urls_with_terms method before using it in a SQL statement, leading to an SQL injection exploitable by low privilege users such as subscriber | |
| Modificada | Media (4.3) | 0.36% | — | Softaculous Speedycache | 11/1/2024 | 17/6/2026 | The SpeedyCache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the speedycache_save_varniship, speedycache_img_update_settings, speedycache_preloading_add_settings, and speedycache_preloading_delete_resource functions in all versions up to, and including,… | |
| Modificada | Media (5.4) | 17% | — | Litespeedtech Litespeed Cache | 11/1/2024 | 17/6/2026 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'esi' shortcode in versions up to, and including, 5.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above… | |
| Modificada | Alta (7.5) | 0.60% | — | Aruba Hispeed Cache | 19/12/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Aruba.It Aruba HiSpeed Cache.This issue affects Aruba HiSpeed Cache: from n/a through 2.0.6. | |
| Modificada | Alta (7.5) | 58% | — | Squid-cache Squid | 14/12/2023 | 17/6/2026 | Squid is a caching proxy for the Web. Due to an Uncontrolled Recursion bug in versions 2.6 through 2.7.STABLE9, versions 3.1 through 5.9, and versions 6.0.1 through 6.5, Squid may be vulnerable to a Denial of Service attack against HTTP Request parsing. This problem allows a remote client to perform Denial of Service… | |
| Modificada | Media (4.3) | 0.32% | — | Softaculous Speedycache | 7/12/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Softaculous Team SpeedyCache – Cache, Optimization, Performance.This issue affects SpeedyCache – Cache, Optimization, Performance: from n/a through 1.1.2. | |
| Modificada | Alta (7.5) | 4.8% | — | Squid-cache Squid | 4/12/2023 | 17/6/2026 | Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with "collapsed_forwarding on" are… |