Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3045▲ 455 respecto a la semana anterior
Críticas / altas1424▲ 188 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)389▲ 174 respecto a la semana anterior
–

456 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)——Cache EnablerAI1/10/20261/10/2026
The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem path in its cache purge routine, and does not confine the resulting deletion to the cache directory, allowing unauthenticated users to delete arbitrary files and directories on sites where another installed…
AplazadaBaja (2.1)0.27%—Kvcache-ai MooncakeAI24/9/202624/9/2026
A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::GetReplicaListByRegex of the component Regular Expression Handler. Executing a manipulation can lead to allocation of resources. The attack may be performed from remote. The exploit has been made…
AplazadaBaja (2.1)0.25%—Kvcache-ai MooncakeAI24/9/202629/9/2026
A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1. This issue affects the function ScopedSegmentAccess::MountSegment of the file segment.cpp of the component MountSegment Request Processing. Performing a manipulation results in improper access controls. The attack is…
AplazadaMedia (5.5)0.29%—Kvcache-ai MooncakeAI24/9/202624/9/2026
A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of the component RPC Path Handler. This manipulation of the argument client_id/segment_id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been publicly…
AplazadaMedia (4.7)0.38%—Litespeedtech Litespeed CacheAI19/9/202621/9/2026
The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all versions up to, and including, 7.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AplazadaMedia (6.5)0.34%—Wpgraphql Smart CacheAI19/9/202621/9/2026
The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied query identifier before storing a persisted query from a request, allowing unauthenticated users to publish arbitrary query documents and claim query aliases before a site's own frontend registers them.
AplazadaBaja (2.3)0.36%—Vinyl-cache Vinyl CacheAI18/9/202622/9/2026
In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type methods of VCL. This can be used as a remote denial of service (DoS) vector to make the child process segfault or assert, and then restart. Effectively exploiting this vulnerability requires prior…
AplazadaAlta (8.2)0.45%—Http-cache-semanticsAI18/9/202623/9/2026
http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs previously fetched by other clients to receive cached responses intended for different…
AplazadaAlta (8.7)0.53%—Http-cache-semanticsAI18/9/202623/9/2026
http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can request the same URL with a large max-stale value to obtain another user's…
Pendiente de análisisMedia (6.5)0.29%—Io.netty Netty-codec-memcacheAI18/9/202625/9/2026
A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types instead of unsigned, as specified by the protocol. A malicious Memcache server can exploit this type mismatch by sending a specially crafted response. This can…
AplazadaMedia (6.5)0.29%—Breeze CacheAI18/9/202618/9/2026
The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested with them, allowing unauthenticated attackers to have a page rendered under their own request context stored under, and served from, the clean URL's…
AplazadaMedia (5.5)0.86%—MemcachedAI14/9/202615/9/2026
A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit has been released…
AplazadaMedia (6.4)0.15%—Aruba Hispeed CacheAI10/9/202610/9/2026
The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Content in all versions up to, and including, 3.0.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject…
AplazadaMedia (5.4)0.33%—Rattler CacheAIPY RattlerAI9/9/202610/9/2026
Rattler is a library that provides common functionality used within the conda ecosystem. `rattler_cache` prior to version 0.9.0 and `py-rattler` prior to version 0.24.0 were vulnerable to package-cache path traversal when handling package metadata from conda channels. During cache materialization, the `ratter_cache`…
Pendiente de análisisAlta (8.1)0.72%—Ansible Community.generalAIMemcachedAIPython-memcachedAI9/9/20269/9/2026
A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached…
AplazadaAlta (7.2)0.50%—Boldgrid W3 Total CacheAI5/9/20268/9/2026
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaAlta (7.2)0.27%—Litespeedtech Litespeed CacheAI3/9/20264/9/2026
Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions.
AplazadaMedia (6.5)0.15%—Wpfastestcache WP Fastest CacheAI1/9/20261/9/2026
The WP Fastest Cache WordPress plugin before 1.5.1 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested with them, allowing unauthenticated attackers to have a page rendered under their own request context stored under, and served from, the clean URL's…
AplazadaMedia (5.3)0.32%—Breeze CacheAI28/8/202628/8/2026
The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request before using it to build the paths of the files it caches, allowing unauthenticated attackers to create files at arbitrary locations on the server, outside the intended cache directory.
AplazadaMedia (6.4)0.33%—Litespeedtech Litespeed CacheAI28/8/202629/8/2026
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>` tag attributes in all versions up to, and including, 7.7. This is due to a flawed regular expression that is used to strip `width` and `height` attributes from images when the "Lazy Load Images" and "Add Missing…
AplazadaAlta (7.2)0.37%—Litespeedtech Litespeed CacheAI28/8/202628/8/2026
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will…
AplazadaAlta (7.2)0.40%—Wpfastestcache WP Fastest CacheAI26/8/202626/8/2026
The WP Fastest Cache – WordPress Cache Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTTP Host Header in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaAlta (7.5)0.37%—Wpfastestcache WP Fastest CacheAI25/8/202626/8/2026
The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build the URLs of the asset files it embeds in the pages it caches, and does not include that header in the cache key, allowing unauthenticated attackers to poison cached pages with references to a server they…
AplazadaCrítica (10)0.57%—Boldgrid W3 Total CacheAI19/8/202626/8/2026
The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name. On Apache, the…
AplazadaAlta (7.2)0.43%—Boldgrid W3 Total CacheAI14/8/202614/8/2026
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will…