Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
459 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.4) | 0.24% | — | Intel Open Cache Acceleration Software | 10/5/2023 | 17/6/2026 | Insertion of sensitive information into log file in the Open CAS software for Linux maintained by Intel before version 22.6.2 may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Media (4.3) | 0.39% | — | Wpfastestcache WP Fastest Cache | 6/4/2023 | 17/6/2026 | The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the deleteCssAndJsCacheToolbar function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to perform cache deletion. | |
| Modificada | Media (4.3) | 0.39% | — | Wpfastestcache WP Fastest Cache | 6/4/2023 | 17/6/2026 | The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the wpfc_clear_cache_of_allsites_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to delete caches. | |
| Modificada | Media (4.3) | 0.39% | — | Wpfastestcache WP Fastest Cache | 6/4/2023 | 17/6/2026 | The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the wpfc_purgecache_varnish_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to purge the varnish… | |
| Modificada | Media (4.3) | 0.39% | — | Wpfastestcache WP Fastest Cache | 6/4/2023 | 17/6/2026 | The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the wpfc_preload_single_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to initiate cache creation. | |
| Modificada | Media (4.3) | 0.23% | — | Wpfastestcache WP Fastest Cache | 6/4/2023 | 17/6/2026 | The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the deleteCssAndJsCacheToolbar function. This makes it possible for unauthenticated attackers to perform cache deletion via a forged… | |
| Modificada | Media (4.3) | 0.23% | — | Wpfastestcache WP Fastest Cache | 6/4/2023 | 17/6/2026 | The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the deleteCacheToolbar function. This makes it possible for unauthenticated attackers to perform cache deletion via a forged request… | |
| Modificada | Media (4.3) | 0.23% | — | Wpfastestcache WP Fastest Cache | 6/4/2023 | 17/6/2026 | The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_clear_cache_of_allsites_callback function. This makes it possible for unauthenticated attackers to clear caches via a forged… | |
| Modificada | Media (4.3) | 0.23% | — | Wpfastestcache WP Fastest Cache | 6/4/2023 | 17/6/2026 | The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_toolbar_save_settings_callback function. This makes it possible for unauthenticated attackers to change cache settings via a… | |
| Modificada | Media (4.3) | 0.23% | — | Wpfastestcache WP Fastest Cache | 6/4/2023 | 17/6/2026 | The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_remove_cdn_integration_ajax_request_callback function. This makes it possible for unauthenticated attackers to change cdn… | |
| Modificada | Media (4.3) | 0.23% | — | Wpfastestcache WP Fastest Cache | 6/4/2023 | 17/6/2026 | The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_pause_cdn_integration_ajax_request_callback function. This makes it possible for unauthenticated attackers to change cdn… | |
| Modificada | Media (4.3) | 0.23% | — | Wpfastestcache WP Fastest Cache | 6/4/2023 | 17/6/2026 | The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_start_cdn_integration_ajax_request_callback function. This makes it possible for unauthenticated attackers to change cdn… | |
| Modificada | Media (4.3) | 0.23% | — | Wpfastestcache WP Fastest Cache | 6/4/2023 | 17/6/2026 | The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_purgecache_varnish_callback function. This makes it possible for unauthenticated attackers to purge the varnish cache via a… | |
| Modificada | Media (4.3) | 0.23% | — | Wpfastestcache WP Fastest Cache | 6/4/2023 | 17/6/2026 | The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_preload_single_save_settings_callback function. This makes it possible for unauthenticated attackers to change cache-related… | |
| Modificada | Media (4.3) | 0.23% | — | Wpfastestcache WP Fastest Cache | 6/4/2023 | 17/6/2026 | The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_preload_single_callback function. This makes it possible for unauthenticated attackers to invoke a cache building action via a… | |
| Modificada | Crítica (9.8) | 0.72% | — | Ibexa Digital Experience PlatformIbexa Ezplatform-http-cache-fastlyIbexa FastlyIbexa EZ Platform Kernel+1 | 12/3/2023 | 17/6/2026 | An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled. | |
| Modificada | Media (6.5) | 0.75% | — | Awesome Libmemcached | 7/3/2023 | 17/6/2026 | libmemcached-awesome is an open source C/C++ client library and tools for the memcached server. `libmemcached` could return data for a previously requested key, if that previous request timed out due to a low `POLL_TIMEOUT`. This issue has been addressed in version 1.1.4. Users are advised to upgrade. There are… | |
| Modificada | Media (5.5) | 0.36% | — | Memcached | 3/2/2023 | 17/6/2026 | Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file. | |
| Modificada | Alta (7.5) | 1.6% | — | Http-cache-semantics Project Http-cache-semantics | 31/1/2023 | 17/6/2026 | This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library. | |
| Modificada | Alta (8.6) | 3.0% | — | Squid-cache Squid | 25/12/2022 | 17/6/2026 | A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed… | |
| Modificada | Media (6.5) | 1.8% | — | Squid-cache Squid | 25/12/2022 | 17/6/2026 | An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, there can be Exposure of Sensitive Information about clients using the proxy via an HTTPS request to an internal cache manager URL. This is fixed in 5.7. | |
| Modificada | Alta (7.5) | 1.0% | — | Varnish-software Varnish CacheVarnish-software Varnish Cache PlusVarnish Cache Project Varnish CacheFedoraproject Fedora+1 | 9/11/2022 | 17/6/2026 | An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests… | |
| Modificada | Alta (7.5) | 1.5% | 💥 PoC | Varnish Cache Project Varnish CacheFedoraproject Fedora | 9/11/2022 | 17/6/2026 | An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish Cache servers by requesting that certain headers are made hop-by-hop, preventing the Varnish Cache servers from forwarding critical headers to the backend. | |
| Modificada | Alta (7.5) | 1.4% | — | Varnish Cache Project Varnish CacheFedoraproject Fedora | 11/8/2022 | 17/6/2026 | In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backend response status line. This is fixed in 7.0.3 and 7.1.1. | |
| Modificada | Media (6.5) | 5.1% | — | Squid-cache SquidDebian Linux | 17/7/2022 | 17/6/2026 | In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses. |