Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 2.1% | — | Jackwrichards FastlymcpAI | 28/4/2026 | 24/7/2026 | A vulnerability has been found in jackwrichards FastlyMCP up to 6f3d0b0e654fc51076badc7fa16c03c461f95620. This impacts an unknown function of the file fastly-mcp.mjs of the component fastly_cli Tool. The manipulation of the argument command leads to os command injection. It is possible to initiate the attack remotely.… | |
| Aplazada | Crítica (9.3) | 0.37% | — | Rekinddns Serverless-dnsAICloudflare WorkersAIDeno DeployAIFastlyAI+1 | 30/9/2025 | 17/6/2026 | serverless-dns is a RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. Versions through abd including 0.1.30 have a vulnerability where the pr.yml GitHub Action interpolates in an unsafe manner untrusted input, specifically the github.event.pull_request.head.repo.clone_url and… | |
| Aplazada | Media (4.3) | 0.14% | — | FastlyAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Fastly Fastly fastly allows Cross Site Request Forgery.This issue affects Fastly: from n/a through <= 1.2.28. | |
| Aplazada | Media (5.3) | 0.27% | — | Fastly Js-computeAI | 26/6/2024 | 17/6/2026 | @fastly/js-compute is a JavaScript SDK and runtime for building Fastly Compute applications. The implementation of several functions were determined to include a use-after-free bug. This bug could allow for unintended data loss if the result of the preceding functions were sent anywhere else, and often results in a… | |
| Aplazada | Media (5.3) | 0.36% | — | FastlyAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25. | |
| Aplazada | Media (4.3) | 0.28% | — | FastlyAI | 3/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25. | |
| Modificada | Crítica (9.8) | 0.72% | — | Ibexa Digital Experience PlatformIbexa Ezplatform-http-cache-fastlyIbexa FastlyIbexa EZ Platform Kernel+1 | 12/3/2023 | 17/6/2026 | An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled. | |
| Modificada | Media (6.1) | 0.55% | — | Fastly | 6/3/2023 | 17/6/2026 | A vulnerability was found in Fastly Plugin up to 0.97 on WordPress. It has been rated as problematic. Affected by this issue is the function post of the file lib/api.php. The manipulation of the argument url leads to cross site scripting. The attack may be launched remotely. Upgrading to version 0.98 is able to… | |
| Modificada | Alta (7.5) | 0.92% | — | Fastly Js-compute | 20/9/2022 | 17/6/2026 | The JS Compute Runtime for Fastly's Compute@Edge platform provides the environment JavaScript is executed in when using the Compute@Edge JavaScript SDK. In versions prior to 0.5.3, the `Math.random` and `crypto.getRandomValues` methods fail to use sufficiently random values. The initial value to seed the PRNG… | |
| Modificada | Media (6.5) | 1.2% | — | Fastly | 14/9/2017 | 17/6/2026 | The Fastly CDN module before 1.2.26 for Magento2, when used with a third-party authentication plugin, might allow remote authenticated users to obtain sensitive information from authenticated sessions via vectors involving caching of redirect responses. |