Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.33% | — | Lachatterie VergerAI | 4/10/2025 | 17/6/2026 | A vulnerability was found in LaChatterie Verger up to 1.2.10. This impacts the function redirectToAuthorization of the file /src/main/services/mcp/oauth/provider.ts. The manipulation of the argument URL results in deserialization. The attack can be executed remotely. The exploit has been made public and could be used.… | |
| Aplazada | Media (4.3) | 0.16% | — | Chat BY ChatweeAI | 30/9/2025 | 17/6/2026 | The Chat by Chatwee plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.3. This is due to missing or incorrect nonce validation on the admin settings page. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request granted… | |
| Aplazada | Alta (8.1) | 0.29% | 💥 PoC | Tawk.to Chatbox WidgetAI | 29/9/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in tawk.to chatbox widget v4 allows attackers to execute arbitrary Javascript in the context of the user's browser via injecting a crafted payload into the vulnerable parameter. | |
| Analizada | Alta (7.5) | 0.30% | — | Librechat | 29/9/2025 | 17/6/2026 | A mass assignment vulnerability exists in danny-avila/librechat, affecting all versions. This vulnerability allows attackers to manipulate sensitive fields by automatically binding user-provided data to internal object properties or database fields without proper filtering. As a result, any extra fields in the request… | |
| Analizada | Media (4.3) | 0.32% | — | Lobehub Lobe Chat | 25/9/2025 | 30/9/2026 | Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.130.1, the project's OIDC redirect handling logic constructs the host and protocol of the final redirect URL based on the X-Forwarded-Host or Host headers and the X-Forwarded-Proto value. In deployments where a reverse proxy… | |
| Aplazada | Media (5.1) | 0.25% | — | Mikecen Wechat-face-recognitionAI | 25/9/2025 | 17/6/2026 | A security flaw has been discovered in MikeCen WeChat-Face-Recognition up to 6e3f72bf8547d80b59e330f1137e4aa505f492c1. This vulnerability affects the function valid of the file wx.php. The manipulation of the argument echostr results in cross site scripting. The attack can be launched remotely. This product does not… | |
| Analizada | Media (5.3) | 0.28% | — | Librechat | 23/9/2025 | 17/6/2026 | danny-avila/librechat is affected by an authorization bypass vulnerability due to improper access control checks. The `checkAccess` function in `api/server/middleware/roles/access.js` uses `permissions.some()` to validate permissions, which incorrectly grants access if only one of multiple required permissions is… | |
| Aplazada | Alta (7.1) | 0.13% | — | Casengo Live Chat SupportAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Casengo Casengo Live Chat Support the-casengo-chat-widget allows Stored XSS.This issue affects Casengo Live Chat Support: from n/a through <= 2.1.4. | |
| Aplazada | Media (4.3) | 0.26% | — | Website Chat Button Kommo IntegrationAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Kommo Website Chat Button: Kommo integration website-chat-button-kommo-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Website Chat Button: Kommo integration: from n/a through <= 1.3.1. | |
| Aplazada | Media (4.3) | 0.16% | — | Cesar Martin Tochat.beAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in César Martín TOCHAT.BE tochat-be allows Cross Site Request Forgery.This issue affects TOCHAT.BE: from n/a through <= 1.3.4. | |
| Aplazada | Media (5.9) | 0.30% | — | Dialogity Free Live ChatAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dialogity Dialogity Free Live Chat dialogity-website-chat allows Stored XSS.This issue affects Dialogity Free Live Chat: from n/a through <= 1.0.3. | |
| Analizada | Media (6.8) | 0.40% | — | Lobehub Lobe Chat | 18/9/2025 | 17/6/2026 | Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.129.4, there is a a cross-site scripting (XSS) vulnerability when handling chat message in lobe-chat that can be escalated to remote code execution on the user’s machine. In lobe-chat, when the response from the server is like… | |
| Aplazada | Media (5.1) | 0.27% | — | Wangchenyi1996 Chat ForumAI | 18/9/2025 | 17/6/2026 | A vulnerability has been found in wangchenyi1996 chat_forum up to 80bdb92f5b460d36cab36e530a2c618acef5afd2. This impacts an unknown function of the file /q.php. Such manipulation of the argument path leads to cross site scripting. The attack may be launched remotely. This product operates on a rolling release basis,… | |
| Analizada | Baja (3.1) | 0.30% | — | Librechat | 11/9/2025 | 17/6/2026 | In version 0.7.8 of danny-avila/librechat, improper authorization controls in the conversation sharing feature allow unauthorized access to other users' conversations if the conversation ID is known. Although UUIDv4 conversation IDs are generated server-side and are difficult to brute force, they can be obtained from… | |
| Analizada | Crítica (9.6) | 0.60% | — | Thinkinai Deepchat | 9/9/2025 | 17/6/2026 | DeepChat is a smart assistant uses artificial intelligence. Prior to version 0.3.5, in the Mermaid chart rendering component, there is a risky operation of directly using `innerHTML` to set user content. Therefore, any malicious content rendered via Mermaid will directly trigger the exploit chain, leading to command… | |
| Aplazada | Media (6.5) | 0.17% | — | Rumbletalk Live Group ChatAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RumbleTalk RumbleTalk Live Group Chat rumbletalk-chat-a-chat-with-themes allows Stored XSS.This issue affects RumbleTalk Live Group Chat: from n/a through <= 6.3.5. | |
| Analizada | Alta (7.5) | 0.41% | — | Rocket.chat | 2/9/2025 | 17/6/2026 | rocket.chat Incorrect Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of rocket.chat. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens… | |
| Aplazada | Baja (2.1) | 0.25% | — | Getgist ChatboxAI | 29/8/2025 | 17/6/2026 | A vulnerability was found in shafhasan chatbox up to 156a39cde62f78532c3265a70eda12c70907e56f. This impacts an unknown function of the file /chat.php. The manipulation of the argument user_id results in sql injection. The attack may be performed from a remote location. The exploit has been made public and could be… | |
| Aplazada | Media (6.5) | 0.17% | — | Alexvtn Wa-chatbox-managerAI | 27/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alexvtn Chatbox Manager wa-chatbox-manager allows Stored XSS.This issue affects Chatbox Manager: from n/a through <= 1.2.6. | |
| Aplazada | Crítica (9.8) | 0.65% | — | MallchatAI | 22/8/2025 | 17/6/2026 | MallChat v1.0-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access API without any token. | |
| Aplazada | Media (6.1) | 0.20% | — | NextchatAI | 22/8/2025 | 17/6/2026 | NextChat contains a cross-site scripting (XSS) vulnerability in the HTMLPreview component of artifacts.tsx that allows attackers to execute arbitrary JavaScript code when HTML content is rendered in the AI chat interface. The vulnerability occurs because user-influenced HTML from AI responses is rendered in an iframe… | |
| Analizada | Crítica (9.6) | 0.68% | — | Thinkinai Deepchat | 19/8/2025 | 17/6/2026 | DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click remote code execution vulnerability. An attacker can exploit this vulnerability by embedding a specially crafted deepchat: URL on any website, including a malicious one they control. When a victim… | |
| Aplazada | Baja (2.1) | 0.31% | — | Codephiliax Chat2dbAI | 19/8/2025 | 17/6/2026 | A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects an unknown function of the file ai/chat2db/server/web/api/controller/data/source/DataSourceController.java of the component JDBC Connection Handler. The manipulation results in sql injection. The attack can be executed remotely. The exploit has… | |
| Analizada | Alta (7.5) | 0.71% | — | Microsoft 365 Copilot Chat | 7/8/2025 | 17/6/2026 | Microsoft 365 Copilot BizChat Information Disclosure Vulnerability | |
| Analizada | Alta (7.5) | 0.61% | — | Microsoft 365 Copilot Chat | 7/8/2025 | 17/6/2026 | Microsoft 365 Copilot BizChat Information Disclosure Vulnerability |