Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
458 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 10% | — | Squid-cache Squid | 4/12/2023 | 17/6/2026 | Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Incorrect Check of Function Return Value bug Squid is vulnerable to a Denial of Service attack against its Helper process management. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known… | |
| Modificada | Alta (7.5) | 88% | — | Squid-cache Squid | 4/12/2023 | 17/6/2026 | Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability. | |
| Modificada | Alta (7.5) | 74% | 💥 Exploit | Wpfastestcache WP Fastest Cache | 4/12/2023 | 17/6/2026 | The WP Fastest Cache WordPress plugin before 1.2.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users. | |
| Modificada | Media (5.4) | 0.41% | — | Elijaa Phpmemcachedadmin | 30/11/2023 | 17/6/2026 | A critical flaw has been identified in elijaa/phpmemcachedadmin affecting version 1.3.0, specifically related to a stored XSS vulnerability. This vulnerability allows malicious actors to insert a carefully crafted JavaScript payload. The issue arises from improper encoding of user-controlled entries in the… | |
| Modificada | Crítica (9.1) | 0.86% | — | Elijaa Phpmemcachedadmin | 30/11/2023 | 17/6/2026 | A Path traversal vulnerability has been reported in elijaa/phpmemcachedadmin affecting version 1.3.0. This vulnerability allows an attacker to delete files stored on the server due to lack of proper verification of user-supplied input. | |
| Modificada | Alta (8.8) | 0.27% | — | Kenthhagstrom Wp-cachecom | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kenth Hagström WP-Cache.Com plugin <= 1.1.1 versions. | |
| Modificada | Alta (7.5) | 6.0% | — | Squid-cache Squid | 6/11/2023 | 17/6/2026 | Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1. Responses triggering this bug are… | |
| Modificada | Alta (7.5) | 5.2% | — | Squid-cache SquidRedhat Enterprise Linux | 3/11/2023 | 17/6/2026 | A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a… | |
| Modificada | Alta (7.5) | 10% | — | Squid-cache SquidRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux Server AUS+1 | 3/11/2023 | 17/6/2026 | Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input. | |
| Modificada | Alta (7.5) | 88% | — | Squid-cache SquidRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+6 | 3/11/2023 | 7/8/2026 | Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication. | |
| Modificada | Media (5.3) | 6.2% | — | Squid-cache SquidRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+4 | 3/11/2023 | 17/6/2026 | SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems. | |
| Modificada | Alta (7.5) | 4.0% | — | Squid-cache Squid | 1/11/2023 | 17/6/2026 | Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of… | |
| Modificada | Crítica (9.8) | 0.76% | — | Memcached | 27/10/2023 | 17/6/2026 | In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n. | |
| Modificada | Alta (7.5) | 0.78% | — | Memcached | 27/10/2023 | 17/6/2026 | In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the "get" substring. | |
| Modificada | Alta (8.8) | 0.84% | — | Geoserver Geowebcache | 26/10/2023 | 17/6/2026 | A vulnerability was found in GeoServer GeoWebCache up to 1.15.1. It has been declared as problematic. This vulnerability affects unknown code of the file /geoserver/gwc/rest.html. The manipulation leads to direct request. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Media (6.1) | 0.33% | — | Extendwings Opcache Dashboard | 18/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Daisuke Takahashi(Extend Wings) OPcache Dashboard plugin <= 0.3.1 versions. | |
| Modificada | Alta (8.8) | 47% | — | All-three Cachet | 11/10/2023 | 17/6/2026 | Cachet, the open-source status page system. Prior to the 2.4 branch, a template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Commit 6fb043e109d2a262ce3974e863c54e9e5f5e0587 of the 2.4 branch contains a patch for this… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (8.8) | 0.25% | — | Palasthotel USE Memcached | 9/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Palasthotel (in person: Edward Bock) Use Memcached plugin <= 1.0.4 versions. | |
| Modificada | Alta (7.5) | 1.1% | — | Memcached | 22/8/2023 | 17/6/2026 | memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP. | |
| Modificada | Alta (7.5) | 1.3% | — | Memcached | 22/8/2023 | 17/6/2026 | Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command. | |
| Modificada | Media (4.3) | 0.53% | — | Wpfastestcache WP Fastest Cache | 9/6/2023 | 17/6/2026 | The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized cache deletion in versions up to, and including, 1.1.2 due to a missing capability check in the deleteCacheToolbar function . This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete the site's… | |
| Modificada | Alta (8.8) | 8.5% | — | Wpfastestcache WP Fastest Cache | 30/5/2023 | 17/6/2026 | The WP Fastest Cache WordPress plugin before 1.1.5 does not have CSRF check in an AJAX action, and does not validate user input before using it in the wp_remote_get() function, leading to a Blind SSRF issue | |
| Modificada | Alta (8.8) | 0.26% | — | Litespeedtech Litespeed Cache | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache plugin <= 5.3 versions. | |
| Modificada | Media (4.4) | 0.24% | — | Intel Open Cache Acceleration Software | 10/5/2023 | 17/6/2026 | Insertion of sensitive information into log file in the Open CAS software for Linux maintained by Intel before version 22.6.2 may allow a privileged user to potentially enable information disclosure via local access. |