Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)2.1%—Jackwrichards FastlymcpAI28/4/202624/7/2026
A vulnerability has been found in jackwrichards FastlyMCP up to 6f3d0b0e654fc51076badc7fa16c03c461f95620. This impacts an unknown function of the file fastly-mcp.mjs of the component fastly_cli Tool. The manipulation of the argument command leads to os command injection. It is possible to initiate the attack remotely.…
AplazadaCrítica (9.3)0.37%—Rekinddns Serverless-dnsAICloudflare WorkersAIDeno DeployAIFastlyAI+130/9/202517/6/2026
serverless-dns is a RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. Versions through abd including 0.1.30 have a vulnerability where the pr.yml GitHub Action interpolates in an unsafe manner untrusted input, specifically the github.event.pull_request.head.repo.clone_url and…
AplazadaMedia (4.3)0.14%—FastlyAI22/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Fastly Fastly fastly allows Cross Site Request Forgery.This issue affects Fastly: from n/a through <= 1.2.28.
AplazadaMedia (5.3)0.27%—Fastly Js-computeAI26/6/202417/6/2026
@fastly/js-compute is a JavaScript SDK and runtime for building Fastly Compute applications. The implementation of several functions were determined to include a use-after-free bug. This bug could allow for unintended data loss if the result of the preceding functions were sent anywhere else, and often results in a…
AplazadaMedia (5.3)0.36%—FastlyAI11/6/202417/6/2026
Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25.
AplazadaMedia (4.3)0.28%—FastlyAI3/6/202417/6/2026
Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25.
ModificadaCrítica (9.8)0.72%—Ibexa Digital Experience PlatformIbexa Ezplatform-http-cache-fastlyIbexa FastlyIbexa EZ Platform Kernel+112/3/202317/6/2026
An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled.
ModificadaMedia (6.1)0.55%—Fastly6/3/202317/6/2026
A vulnerability was found in Fastly Plugin up to 0.97 on WordPress. It has been rated as problematic. Affected by this issue is the function post of the file lib/api.php. The manipulation of the argument url leads to cross site scripting. The attack may be launched remotely. Upgrading to version 0.98 is able to…
ModificadaAlta (7.5)0.92%—Fastly Js-compute20/9/202217/6/2026
The JS Compute Runtime for Fastly's Compute@Edge platform provides the environment JavaScript is executed in when using the Compute@Edge JavaScript SDK. In versions prior to 0.5.3, the `Math.random` and `crypto.getRandomValues` methods fail to use sufficiently random values. The initial value to seed the PRNG…
ModificadaMedia (6.5)1.2%—Fastly14/9/201717/6/2026
The Fastly CDN module before 1.2.26 for Magento2, when used with a third-party authentication plugin, might allow remote authenticated users to obtain sensitive information from authenticated sessions via vectors involving caching of redirect responses.