Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.44% | — | Chatra Live ChatAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chatra Chatra Live Chat + ChatBot + Cart Saver allows Stored XSS. This issue affects Chatra Live Chat + ChatBot + Cart Saver: from n/a through 1.0.11. | |
| Aplazada | Crítica (9.1) | 0.50% | 💥 PoC | Webfactory Aibuddy Openai ChatgptAI | 3/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WebFactory AiBud WP aibuddy-openai-chatgpt allows Upload a Web Shell to a Web Server.This issue affects AiBud WP: from n/a through <= 1.9. | |
| Analizada | Media (6.1) | 0.29% | — | Cisco Enterprise Chat AND Email | 2/7/2025 | 17/6/2026 | A vulnerability in the web UI of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web UI does not properly validate user-supplied input. An attacker could… | |
| Analizada | Baja (2) | 0.67% | — | Chatchat-space Langchain-chatchat | 29/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This issue affects some unknown processing of the file /v1/file. The manipulation of the argument flag leads to path traversal. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (2.1) | 0.58% | — | Chatchat-space Langchain-chatchat | 29/6/2025 | 17/6/2026 | A vulnerability classified as problematic was found in chatchat-space Langchain-Chatchat up to 0.3.1. This vulnerability affects unknown code of the file /v1/files?purpose=assistants. The manipulation leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Baja (2.1) | 0.58% | — | Chatchat-space Langchain-chatchat | 29/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This affects the function upload_temp_docs of the file /knowledge_base/upload_temp_docs of the component Backend. The manipulation of the argument flag leads to path traversal. It is possible to initiate the attack… | |
| Aplazada | Media (4.3) | 0.27% | — | Quantumcloud ChatbotAI | 27/6/2025 | 17/6/2026 | Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ChatBot: from n/a through <= 6.7.3. | |
| Aplazada | Alta (7.2) | 0.29% | — | Wise ChatAI | 17/6/2025 | 17/6/2026 | The Wise Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Media (6.4) | 0.27% | — | Click TO ChatAI | 14/6/2025 | 17/6/2026 | The Click to Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-no_number’ parameter in all versions up to, and including, 4.22 to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Media (5.5) | 0.21% | — | Rocket.chatAI | 11/6/2025 | 17/6/2026 | The macOS Rocket.Chat application is affected by a vulnerability that allows bypassing Transparency, Consent, and Control (TCC) policies, enabling the exploitation or abuse of permissions specified in its entitlements (e.g., microphone, camera, automation, network client). Since Rocket.Chat was not signed with the… | |
| Analizada | Baja (2.1) | 0.60% | — | Rocket.chat | 9/6/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in RocketChat up to 7.6.1. This issue affects the function parseMessage of the file /apps/meteor/app/irc/server/servers/RFC2813/parseMessage.js. The manipulation of the argument line leads to inefficient regular expression complexity. The attack may… | |
| Analizada | Media (6.8) | 0.29% | — | Keepersecurity Keeperchat | 9/6/2025 | 17/6/2026 | An issue in KeeperChat IOS Application v.5.8.8 allows a physically proximate attacker to escalate privileges via the Biometric Authentication Module | |
| Analizada | Baja (2.1) | 0.50% | — | Fabian Chat System | 9/6/2025 | 17/6/2026 | A vulnerability was found in code-projects Chat System up to 1.0 and classified as critical. This issue affects some unknown processing of the file /user/confirm_password.php. The manipulation of the argument cid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Aplazada | Media (5.3) | 0.32% | — | RaychatAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in raychat Raychat raychat allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Raychat: from n/a through <= 2.1.0. | |
| Analizada | Media (5.4) | 0.27% | — | Ninjateam Chat FOR Telegram | 30/5/2025 | 17/6/2026 | The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Alta (7.5) | 0.55% | — | Indie Plugins Whatsapp Click TO ChatAI | 19/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Indie_Plugins WhatsApp Click to Chat Plugin for WordPress wpt-whatsapp.This issue affects WhatsApp Click to Chat Plugin for WordPress: from n/a through <= 2.2.12. | |
| Analizada | Media (6.5) | 0.65% | — | Openai Chatgpt | 19/5/2025 | 17/6/2026 | The ChatGPT system through 2025-03-30 performs inline rendering of SVG documents (instead of, for example, rendering them as text inside a code block), which enables HTML injection within most modern graphical web browsers. | |
| Analizada | Alta (7.5) | 0.47% | — | Kainex Wise Chat | 17/5/2025 | 17/6/2026 | The Wise Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.3 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory which can contain file… | |
| Aplazada | Media (6.4) | 0.30% | — | Kiwichat NextclientAI | 2/5/2025 | 17/6/2026 | The KiwiChat NextClient plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Media (5.4) | 0.16% | — | Nghialuu Zalo Official Live ChatAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in nghialuu Zalo Official Live Chat zalo-official-live-chat allows Cross Site Request Forgery.This issue affects Zalo Official Live Chat: from n/a through <= 1.0.0. | |
| Aplazada | Alta (8.8) | 0.47% | — | Xelion WebchatAI | 24/4/2025 | 17/6/2026 | The Xelion Webchat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the xwc_save_settings() function in all versions up to, and including, 9.1.0. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Analizada | Crítica (9.8) | 0.60% | — | Landchat | 17/4/2025 | 17/6/2026 | A RCE vulnerability in the core application in LandChat 3.25.12.18 allows an unauthenticated attacker to execute system code via remote network access. | |
| Aplazada | Alta (8.8) | 0.40% | — | Jauhari Xelion Xelion WebchatAI | 17/4/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Jauhari Xelion Xelion Webchat xelion-webchat allows Privilege Escalation.This issue affects Xelion Webchat: from n/a through <= 9.1.0. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Videowhisper Paid Videochat Turnkey SiteAI | 17/4/2025 | 17/6/2026 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-webcams allows Password Recovery Exploitation.This issue affects Paid Videochat Turnkey Site: from n/a through <= 7.3.11. | |
| Aplazada | Crítica (9.3) | 0.45% | — | Claudio Adrian Marrero ChatliveAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Claudio Adrian Marrero CHATLIVE chatlive allows SQL Injection.This issue affects CHATLIVE: from n/a through <= 2.0.1. |