Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.18% | — | Apt-cacher-ng Project Apt-cacher-ng | 29/9/2025 | 17/6/2026 | Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows malicious scripts (XSS) to be executed in “/html/<filename>.html”. | |
| Analizada | Media (5.1) | 0.18% | — | Apt-cacher-ng Project Apt-cacher-ng | 29/9/2025 | 17/6/2026 | Reflected Cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows an attacker to execute malicious scripts (XSS) in the web management application. The vulnerability is caused by improper handling of GET inputs included in the URL in “/acng-report.html”. | |
| Modificada | Media (5.5) | 0.26% | — | Apt-cacher-ng Project Apt-cacher-ngOpensuse Backports | 23/1/2020 | 17/6/2026 | The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root privileges. This can allow local attackers to influence the outcome of these operations. This issue affects: openSUSE Leap 15.1 apt-cacher-ng versions prior to 3.1-lp151.3.3.1. | |
| Modificada | Media (5.5) | 0.47% | — | Apt-cacher-ng Project Apt-cacher-ngDebian LinuxOpensuse BackportsOpensuse Leap | 21/1/2020 | 17/6/2026 | apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to apt-cacher-ng via TCP on localhost port 3142, even if the explicit SocketPath=/var/run/apt-cacher-ng/socket command-line option is passed.… | |
| Modificada | Media (6.1) | 0.71% | — | Apt-cacher-ng Project Apt-cacher-ngApt-cacher Project Apt-cacher | 5/4/2017 | 17/6/2026 | apt-cacher before 1.7.15 and apt-cacher-ng before 3.4 allow HTTP response splitting via encoded newline characters, related to lack of blocking for the %0[ad] regular expression. | |
| Modificada | Media (4.3) | 0.98% | — | Debian Apt-cacher | 6/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in job.cc in apt-cacher-ng 0.7.26 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Alta (7.5) | 2.1% | — | Debian Apt-cacher | 5/8/2005 | 16/6/2026 | Unknown vulnerability in apt-cacher in Debian 3.1, related to "missing input sanitising," allows remote attackers to execute arbitrary commands on the caching server. |