Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2577▼ 295 respecto a la semana anterior
Críticas / altas1354▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (2.3) | 0.47% | — | Varnish CacheAIVinyl-cache Vinyl CacheAI | 3/6/2026 | 22/7/2026 | In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync attack (request smuggling), which in turn can be used for cache poisoning, authentication bypass, or possibly even information disclosure and manipulation. The attack… | |
| Analizada | Alta (7.5) | 0.40% | — | Varnish-software Varnish Enterprise | 12/4/2026 | 17/6/2026 | Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The headerplus.write_req0() function from vmod_headerplus updates the underlying req0, which is normally the original read-only request from which req is derived (readable and writable from VCL). This is… | |
| Analizada | Alta (7.5) | 0.40% | — | Varnish-software Varnish EnterpriseVinyl-cache Vinyl Cache | 12/4/2026 | 17/6/2026 | Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for certain amounts of prefetched data. The setup of an HTTP/2 session starts with a speculative HTTP/1 transport, and upon upgrading to h2 the HTTP/1 request is repurposed as stream… | |
| Analizada | Crítica (9.8) | 0.37% | — | Varnish-software Varnish EnterpriseVinyl-cache Vinyl Cache | 27/3/2026 | 17/6/2026 | Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass. | |
| Aplazada | Media (5.3) | 0.39% | — | Cloudpanel CLP Varnish CacheAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in CloudPanel CLP Varnish Cache clp-varnish-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CLP Varnish Cache: from n/a through <= 1.0.2. | |
| Aplazada | Media (5.3) | 0.71% | — | Razvan Stanga Varnish Nginx Proxy CachingAI | 31/12/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Razvan Stanga Varnish/Nginx Proxy Caching vcaching allows Retrieve Embedded Sensitive Data.This issue affects Varnish/Nginx Proxy Caching: from n/a through <= 1.8.3. | |
| Aplazada | Alta (7.1) | 0.13% | — | Dsingh Purge Varnish CacheAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dsingh Purge Varnish Cache purge-varnish allows Stored XSS.This issue affects Purge Varnish Cache: from n/a through <= 2.6. | |
| Aplazada | Media (5.9) | 0.22% | — | Razvan Stanga Varnish Nginx Proxy CachingAI | 28/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Razvan Stanga Varnish/Nginx Proxy Caching vcaching allows Stored XSS.This issue affects Varnish/Nginx Proxy Caching: from n/a through <= 1.8.3. | |
| Aplazada | Media (5.4) | 0.36% | — | Varnish CacheAIVarnish-software Varnish EnterpriseAI | 13/5/2025 | 17/6/2026 | Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries. | |
| Aplazada | Alta (7.1) | 0.13% | — | Admingeekz Varnish-wpAI | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AdminGeekZ Varnish WordPress varnish-wp allows Cross Site Request Forgery.This issue affects Varnish WordPress: from n/a through <= 1.7. | |
| Analizada | Alta (7.5) | 0.34% | — | Varnish-software Varnish Enterprise | 21/3/2025 | 17/6/2026 | Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on ephemeral MSE4 stevedore objects. | |
| Modificada | Media (4.8) | 0.31% | — | Varnish-software Varnish EnterpriseVarnish Cache Project Varnish Cache | 21/3/2025 | 17/6/2026 | Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests. | |
| Analizada | Media (5.3) | 0.37% | — | Advanced Varnish Project Advanced Varnish | 9/1/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Advanced Varnish allows Forceful Browsing.This issue affects Advanced Varnish: from 0.0.0 before 4.0.11. | |
| Aplazada | Alta (7.5) | 3.7% | — | Varnish CacheAIVarnish EnterpriseAI | 24/3/2024 | 17/6/2026 | Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, allows credits exhaustion for an HTTP/2 connection control flow window, aka a Broke Window Attack. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (6.5) | 0.60% | — | Varnish-software Varnish EnterpriseVarnish-software Vmod Digest | 23/8/2023 | 17/6/2026 | libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access during base64 decoding, leading to both authentication bypass and information disclosure; however, the exact attack surface will depend on the particular VCL (Varnish Configuration Language)… | |
| Modificada | Alta (7.5) | 1.0% | — | Varnish-software Varnish CacheVarnish-software Varnish Cache PlusVarnish Cache Project Varnish CacheFedoraproject Fedora+1 | 9/11/2022 | 17/6/2026 | An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests… | |
| Modificada | Alta (7.5) | 1.5% | — | Varnish Cache Project Varnish CacheFedoraproject Fedora | 9/11/2022 | 17/6/2026 | An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish Cache servers by requesting that certain headers are made hop-by-hop, preventing the Varnish Cache servers from forwarding critical headers to the backend. | |
| Modificada | Alta (7.5) | 1.4% | — | Varnish Cache Project Varnish CacheFedoraproject Fedora | 11/8/2022 | 17/6/2026 | In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backend response status line. This is fixed in 7.0.3 and 7.1.1. | |
| Modificada | Media (5.3) | 0.76% | — | Mittwald Varnishcache | 19/2/2022 | 17/6/2026 | An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content element renderer component does not include an access check. This allows an unauthenticated user to render various content elements, resulting in insecure direct object reference (IDOR), with the… | |
| Modificada | Crítica (9.1) | 2.0% | — | Varnish-software Varnich CacheVarnish-software Varnish CacheVarnish-software Varnish Cache PlusVarnish Cache Project Varnish Cache+2 | 26/1/2022 | 17/6/2026 | In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections. | |
| Modificada | Media (6.5) | 1.6% | — | Varnish-cache Varnish CacheVarnish-software Varnish CacheVarnish Cache Project Varnish CacheFedoraproject Fedora+1 | 14/7/2021 | 17/6/2026 | Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x before 6.6.1, and 6.0 LTS before 6.0.8. | |
| Modificada | Alta (7.5) | 1.5% | — | Varnish-cache Varnish-modulesVarnish-cache Varnish-modules KlarlackFedoraproject Fedora | 16/3/2021 | 17/6/2026 | Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not affect organizations that only install the Varnish Cache product; however, it is common to install both Varnish Cache and varnish-modules. Specifically, an assertion failure… | |
| Modificada | Alta (7.5) | 2.2% | — | Varnish-cache Varnish CacheVarnish-software Varnish CacheOpensuse Backports SLEOpensuse Leap+1 | 8/4/2020 | 17/6/2026 | An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss. | |
| Modificada | Alta (7.5) | 1.8% | — | Varnish-cache Varnish CacheVarnish-software Varnish CacheOpensuse Backports SLEOpensuse Leap | 8/4/2020 | 17/6/2026 | An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such… |