Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.45% | — | Librechat | 5/8/2025 | 17/6/2026 | LibreChat is a ChatGPT clone with additional features. In versions 0.0.6 through 0.7.7-rc1, an exposed testing endpoint allows reading arbitrary chats directly from the Meilisearch engine. The endpoint /api/search/test allows for direct access to stored chats in the Meilisearch engine without proper access control.… | |
| Modificada | Crítica (9.8) | 0.53% | — | X-D LAB Langchain-chatglm-webui | 1/8/2025 | 5/7/2026 | Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive files via supplying a crafted request. | |
| Aplazada | Crítica (9.3) | 1.9% | 💥 Exploit | FlashchatAI | 31/7/2025 | 16/6/2026 | An unauthenticated arbitrary file upload vulnerability exists in FlashChat versions 6.0.2 and 6.0.4 through 6.0.8. The upload.php endpoint fails to properly validate file types and authentication, allowing attackers to upload malicious PHP scripts. Once uploaded, these scripts can be executed remotely, resulting in… | |
| Analizada | Baja (2.1) | 0.42% | — | Fabian Public Chat Room | 25/7/2025 | 17/6/2026 | A vulnerability has been found in code-projects Public Chat Room 1.0 and classified as critical. This vulnerability affects unknown code of the file send_message.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may… | |
| Aplazada | Media (6.5) | 0.35% | 💥 PoC | Aibox LLM ChatAI | 22/7/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in AIBOX LLM chat (chat.aibox365.cn) through 2025-05-27, allowing attackers to hijack accounts through stolen JWT tokens. | |
| Aplazada | Media (6.1) | 0.28% | 💥 PoC | Chatgpt UnliAI | 22/7/2025 | 17/6/2026 | Self Cross Site Scripting (XSS) vulnerability in ChatGPT Unli (ChatGPTUnli.com) thru 2025-05-26 allows attackers to execute arbitrary code via a crafted SVG file to the chat interface. | |
| Aplazada | Media (6.1) | 0.28% | 💥 PoC | Chatplayground AIAI | 22/7/2025 | 17/6/2026 | Self Cross-Site Scripting (XSS) vulnerability in ChatPlayground.ai through 2025-05-24, allows attackers to execute arbitrary code and gain sensitive information via a crafted SVG file contents sent through the chat component. | |
| Analizada | Baja (2) | 0.33% | — | Fabian Public Chat Room | 22/7/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in code-projects Public Chat Room 1.0. This affects an unknown part of the file /send_message.php. The manipulation of the argument chat_msg/your_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Analizada | Media (5.5) | 0.55% | — | Fabian Public Chat Room | 22/7/2025 | 17/6/2026 | A vulnerability was found in code-projects Public Chat Room 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.5) | 1.5% | 💥 Exploit | Livehelperchat Live Helper Chat | 21/7/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Alias Nick parameter. | |
| Analizada | Media (5.4) | 0.92% | 💥 Exploit | Livehelperchat Live Helper Chat | 21/7/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the operator name parameter. | |
| Analizada | Media (5.4) | 0.92% | 💥 Exploit | Livehelperchat Live Helper Chat | 21/7/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload. | |
| Analizada | Media (5.4) | 0.92% | 💥 Exploit | Livehelperchat Live Helper Chat | 21/7/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter. | |
| Analizada | Media (5.4) | 0.95% | 💥 Exploit | Livehelperchat Live Helper Chat | 21/7/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Surname parameter under the Recipient' Lists. | |
| Analizada | Media (5.4) | 0.97% | 💥 Exploit | Livehelperchat Live Helper Chat | 21/7/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Telegram Bot Username parameter. | |
| Aplazada | Crítica (9.3) | 1.7% | 💥 Exploit | AchatAI | 16/7/2025 | 17/6/2026 | A stack-based buffer overflow exists in Achat v0.150 in its default configuration. By sending a specially crafted message to the UDP port 9256, an attacker can overwrite the structured exception handler (SEH) due to insufficient bounds checking on user-supplied input leading to remote code execution. | |
| Aplazada | Crítica (9.8) | 0.55% | — | Guru Team Site Chat ON TelegramAI | 16/7/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram site-chat-on-telegram allows Object Injection.This issue affects Site Chat on Telegram: from n/a through <= 1.0.4. | |
| Aplazada | Media (5.4) | 0.24% | — | Alexvtn Wa-chatbox-managerAI | 16/7/2025 | 17/6/2026 | Missing Authorization vulnerability in alexvtn Chatbox Manager wa-chatbox-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chatbox Manager: from n/a through <= 1.2.5. | |
| Analizada | Baja (2.1) | 0.35% | — | Fabian Chat System | 13/7/2025 | 17/6/2026 | A vulnerability was found in code-projects Chat System 1.0 and classified as critical. This issue affects some unknown processing of the file /user/update_account.php. The manipulation of the argument musername leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Aplazada | Baja (2.1) | 0.38% | — | Kone-net Go-chatAI | 11/7/2025 | 17/6/2026 | A vulnerability was found in kone-net go-chat up to f9e58d0afa9bbdb31faf25e7739da330692c4c63. It has been declared as critical. This vulnerability affects the function GetFile of the file go-chat/api/v1/file_controller.go of the component Endpoint. The manipulation of the argument fileName leads to path traversal. The… | |
| Aplazada | Baja (2) | 0.28% | — | Livehelperchat LHC PHP ResqueAI | 11/7/2025 | 17/6/2026 | A vulnerability was found in LiveHelperChat lhc-php-resque Extension up to ee1270b35625f552425e32a6a3061cd54b5085c4. It has been classified as problematic. This affects an unknown part of the file /site_admin/lhcphpresque/list/ of the component List Handler. The manipulation of the argument queue name leads to cross… | |
| Analizada | Baja (2.1) | 0.42% | — | Fabian Chat System | 8/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Chat System 1.0. Affected by this issue is some unknown functionality of the file /user/send_message.php. The manipulation of the argument msg leads to sql injection. The attack may be launched remotely. The exploit has been disclosed… | |
| Analizada | Baja (2.1) | 0.42% | — | Fabian Chat System | 8/7/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Chat System 1.0. Affected by this vulnerability is an unknown functionality of the file /user/addmember.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public… | |
| Analizada | Baja (2.1) | 0.44% | — | Fabian Chat System | 8/7/2025 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Chat System 1.0. Affected is an unknown function of the file /user/fetch_member.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Baja (2.1) | 0.44% | — | Fabian Chat System | 8/7/2025 | 17/6/2026 | A vulnerability was found in code-projects Chat System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /user/fetch_chat.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may… |