Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.21% | — | Lmsys FastchatAI | 16/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in lm-sys fastchat up to 0.2.36. This vulnerability affects the function split_files/apply_delta_low_cpu_mem of the file fastchat/model/apply_delta.py. The manipulation leads to deserialization. An attack has to be approached locally. | |
| Aplazada | Alta (7.1) | 0.19% | — | Css-tricks Chat2AI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Chat2 Chat2 chat2 allows Cross Site Request Forgery.This issue affects Chat2: from n/a through <= 4.0. | |
| Aplazada | Alta (7.1) | 0.19% | — | Reve ChatAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in REVE Chat REVE Chat revechat allows Stored XSS.This issue affects REVE Chat: from n/a through <= 6.4.4. | |
| Aplazada | Alta (7.1) | 0.21% | — | Sodena Frescochat Live ChatAISodena Flexytalk-widgetAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in sodena FrescoChat Live Chat flexytalk-widget allows Stored XSS.This issue affects FrescoChat Live Chat: from n/a through <= 3.2.6. | |
| Aplazada | Media (5.9) | 0.41% | — | Socialintents Live-chat-support-by-social-intentsAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in socialintents Social Intents live-chat-support-by-social-intents allows Stored XSS.This issue affects Social Intents: from n/a through <= 1.6.19. | |
| Analizada | Alta (7.5) | 0.65% | — | Cisco Enterprise Chat AND Email | 2/4/2025 | 17/6/2026 | A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper validation of user-supplied input to chat entry points. An attacker could exploit this vulnerability by… | |
| Aplazada | Media (4.3) | 0.40% | — | Team Atomchat AtomchatAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Team AtomChat AtomChat atomchat allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AtomChat: from n/a through <= 1.1.7. | |
| Aplazada | Media (4.3) | 0.28% | — | Chatwee ChatAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Chatwee Chat by Chatwee chatwee allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chat by Chatwee: from n/a through <= 2.1.3. | |
| Aplazada | Media (6.5) | 0.26% | — | Team Atomchat AtomchatAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team AtomChat AtomChat atomchat allows Stored XSS.This issue affects AtomChat: from n/a through <= 1.1.8. | |
| Aplazada | Media (6.5) | 0.20% | — | Ninjateam Click TO Chat WP Support ALL IN ONE Floating WidgetAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ninja Team Click to Chat – WP Support All-in-One Floating Widget support-chat allows Stored XSS.This issue affects Click to Chat – WP Support All-in-One Floating Widget: from n/a through <= 2.3.4. | |
| Aplazada | Media (5.3) | 0.46% | — | Alexvtn Wa-chatbox-managerAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in alexvtn Chatbox Manager wa-chatbox-manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Chatbox Manager: from n/a through <= 1.2.2. | |
| Aplazada | Alta (7.1) | 0.36% | — | Dangngocbinh Zalo Live ChatAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dang Ngoc Binh Zalo Live Chat zalo-live-chat allows Reflected XSS.This issue affects Zalo Live Chat: from n/a through <= 1.1.0. | |
| Analizada | Media (6.5) | 0.59% | — | Gaizhenbiao Chuanhuchatgpt | 20/3/2025 | 17/6/2026 | A Denial of Service (DoS) vulnerability exists in the file upload feature of gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large filename, the server becomes overwhelmed… | |
| Analizada | Media (6.5) | 0.48% | — | Gaizhenbiao Chuanhuchatgpt | 20/3/2025 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability was discovered in gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability allows an attacker to construct a response link by saving the response in a folder named after the SHA-1 hash of the target URL. This enables the attacker to access the response directly,… | |
| Analizada | Alta (8.1) | 0.62% | — | Gaizhenbiao Chuanhuchatgpt | 20/3/2025 | 17/6/2026 | An authentication bypass vulnerability exists in gaizhenbiao/ChuanhuChatGPT, as of commit 3856d4f, allowing any user to read and delete other users' chat history. The vulnerability arises because the username is provided via an HTTP request from the client side, rather than being read from a secure source like a… | |
| Analizada | Media (6.5) | 0.64% | — | Gaizhenbiao Chuanhuchatgpt | 20/3/2025 | 17/6/2026 | An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability allows any user to restart the server at will, leading to a complete loss of availability. The issue arises because the function responsible for restarting the server is not properly guarded by an admin… | |
| Analizada | Media (5.4) | 0.57% | — | Gaizhenbiao Chuanhuchatgpt | 20/3/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, affecting version git 20b2e02. The vulnerability arises from improper sanitization of HTML tags in chat history uploads. Specifically, the sanitization logic fails to handle HTML tags within code blocks correctly,… | |
| Modificada | Alta (8.8) | 0.59% | — | Gaizhenbiao Chuanhuchatgpt | 20/3/2025 | 17/6/2026 | A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. This issue arises due to improper handling of session data and lack of access control mechanisms, enabling attackers to view and manipulate chat histories of other users. | |
| Analizada | Media (5.4) | 0.42% | — | Gaizhenbiao Chuanhuchatgpt | 20/3/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability allows an attacker to upload a malicious HTML file containing JavaScript code, which is then executed when the file is accessed. This can lead to the execution of arbitrary JavaScript in the… | |
| Analizada | Media (5.3) | 0.50% | — | Librechat | 20/3/2025 | 17/6/2026 | A vulnerability in danny-avila/librechat prior to version 0.7.6 allows for logs debug injection. The parameters sessionId, fileId, userId, and file_id in the /code/download/:sessionId/:fileId and /download/:userId/:file_id APIs are not validated or filtered, leading to potential log injection attacks. This can cause… | |
| En análisis | Alta (7.5) | 0.75% | — | Lm-sys Fastchat | 20/3/2025 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability was identified in the lm-sys/fastchat web server, specifically in the affected version git 2c68a13. This vulnerability allows an attacker to access internal server resources and data that are otherwise inaccessible, such as AWS metadata credentials. | |
| Analizada | Alta (7.5) | 0.69% | — | Lm-sys Fastchat | 20/3/2025 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in lm-sys/fastchat version 0.2.36. The vulnerability is present in the `/queue/join?` endpoint, where insufficient validation of the path parameter allows an attacker to send crafted requests. This can lead to unauthorized access to internal networks or the AWS… | |
| Analizada | Media (6.5) | 0.87% | — | Librechat | 20/3/2025 | 17/6/2026 | An unhandled exception in the danny-avila/librechat repository, version git 600d217, can cause the server to crash, leading to a full denial of service. This issue occurs when certain API endpoints receive malformed input, resulting in an uncaught exception. Although a valid JWT is required to exploit this… | |
| Modificada | Alta (7.5) | 0.92% | — | Librechat | 20/3/2025 | 17/6/2026 | A vulnerability in danny-avila/librechat version git a1647d7 allows an unauthenticated attacker to cause a denial of service by sending a crafted payload to the server. The middleware `checkBan` is not surrounded by a try-catch block, and an unhandled exception will cause the server to crash. This issue is fixed in… | |
| Modificada | Alta (7.5) | 0.53% | — | Librechat | 20/3/2025 | 17/6/2026 | In danny-avila/librechat version git 0c2a583, there is an improper input validation vulnerability. The application uses multer middleware for handling multipart file uploads. When using in-memory storage (the default setting for multer), there is no limit on the upload file size. This can lead to a server crash due to… |