Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

458 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.26%—Litespeedtech Litespeed Cache5/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through <= 6.5.0.2.
AnalizadaMedia (4.8)0.28%—Litespeedtech Litespeed Cache25/9/202417/6/2026
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all versions up to, and including, 6.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to…
AnalizadaAlta (7.5)0.81%💥 PoCBoldgrid W3 Total Cache25/9/202417/6/2026
The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visible plugin source. This can allow unauthenticated attackers to impersonate W3 Total Cache and gain access to user account…
ModificadaMedia (5.4)0.18%—Softaculous Speedycache26/8/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Softaculous SpeedyCache speedycache.This issue affects SpeedyCache: from n/a through <= 1.1.8.
ModificadaCrítica (9.8)68%💥 ExploitLitespeedtech Litespeed Cache21/8/202417/6/2026
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1.
ModificadaMedia (5.4)0.18%—Litespeedtech Litespeed Cache24/7/202417/6/2026
The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0.1. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to update the token setting and inject malicious JavaScript via a forged request…
ModificadaMedia (6.3)6.3%—Squid-cache Squid25/6/202417/6/2026
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Out-of-bounds Write error when assigning ESI variables, Squid is susceptible to a Memory Corruption error. This error can lead to a Denial of Service attack.
AplazadaAlta (7.2)0.94%—Wpfastestcache WP Fastest CacheAI23/5/202417/6/2026
The WP Fastest Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.6 via the specificDeleteCache function. This makes it possible for authenticated attackers to delete arbitrary files on the server, which can include wp-config.php files of the affected site or…
AplazadaMedia (4.3)0.19%—Creative Motion Clearfy CacheAI17/5/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Creative Motion Clearfy Cache.This issue affects Clearfy Cache: from n/a through 2.2.1.
ModificadaMedia (5.3)0.41%—Litespeedtech Litespeed Cache16/4/202417/6/2026
Missing Authorization vulnerability in LiteSpeed Technologies LiteSpeed Cache.This issue affects LiteSpeed Cache: from n/a through 5.7.
ModificadaMedia (6.1)55%💥 ExploitLitespeedtech Litespeed Cache16/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 5.7.
AplazadaAlta (7.5)3.7%—Varnish CacheAIVarnish EnterpriseAI24/3/202417/6/2026
Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, allows credits exhaustion for an HTTP/2 connection control flow window, aka a Broke Window Attack.
ModificadaMedia (6.1)0.19%—Optimole Super Page Cache21/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Optimole Super Page Cache for Cloudflare allows Stored XSS.This issue affects Super Page Cache for Cloudflare: from n/a through 4.7.5.
AplazadaCrítica (9.1)0.32%—Rocket.chat AuditAIFilecachetoolsAI18/3/202417/6/2026
Rocket.Chat.Audit through 5ad78e8 depends on filecachetools, which does not exist in PyPI.
ModificadaAlta (7.5)65%—Squid-cache SquidFedoraproject FedoraNetapp Bluexp6/3/202417/6/2026
Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack against HTTP Chunked decoder due to an uncontrolled recursion bug. This problem allows a remote attacker to cause Denial of Service when sending a crafted, chunked, encoded HTTP…
AnalizadaAlta (7.5)88%—Squid-cache SquidNetapp Bluexp14/2/202417/6/2026
Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into Unsafe Value bug ,Squid may be vulnerable to a Denial of Service attack against HTTP header parsing. This problem allows a remote client or a remote server to perform Denial of Service when sending…
ModificadaMedia (6.5)60%—Squid-cache Squid24/1/202417/6/2026
Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid…
ModificadaMedia (6.1)0.25%—Wpfastestcache WP Fastest Cache16/1/202417/6/2026
The WP Fastest Cache WordPress plugin before 0.9.5 is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action, and does not sanitise and escape some the options available via the action, which could allow attackers to make logged in high privilege users call it and set a Cross-Site Scripting payload
ModificadaAlta (8.8)1.2%—Wpfastestcache WP Fastest Cache16/1/202417/6/2026
The WP Fastest Cache WordPress plugin before 0.9.5 does not escape user input in the set_urls_with_terms method before using it in a SQL statement, leading to an SQL injection exploitable by low privilege users such as subscriber
ModificadaMedia (4.3)0.36%—Softaculous Speedycache11/1/202417/6/2026
The SpeedyCache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the speedycache_save_varniship, speedycache_img_update_settings, speedycache_preloading_add_settings, and speedycache_preloading_delete_resource functions in all versions up to, and including,…
ModificadaMedia (5.4)17%—Litespeedtech Litespeed Cache11/1/202417/6/2026
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'esi' shortcode in versions up to, and including, 5.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above…
ModificadaAlta (7.5)0.60%—Aruba Hispeed Cache19/12/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Aruba.It Aruba HiSpeed Cache.This issue affects Aruba HiSpeed Cache: from n/a through 2.0.6.
ModificadaAlta (7.5)58%—Squid-cache Squid14/12/202317/6/2026
Squid is a caching proxy for the Web. Due to an Uncontrolled Recursion bug in versions 2.6 through 2.7.STABLE9, versions 3.1 through 5.9, and versions 6.0.1 through 6.5, Squid may be vulnerable to a Denial of Service attack against HTTP Request parsing. This problem allows a remote client to perform Denial of Service…
ModificadaMedia (4.3)0.32%—Softaculous Speedycache7/12/202317/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Softaculous Team SpeedyCache – Cache, Optimization, Performance.This issue affects SpeedyCache – Cache, Optimization, Performance: from n/a through 1.1.2.
ModificadaAlta (7.5)4.8%—Squid-cache Squid4/12/202317/6/2026
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with "collapsed_forwarding on" are…
Orbitaley — Vulnerabilidades