Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 1.8% | — | Librechat | 20/3/2025 | 17/6/2026 | A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to improper sanitization of file paths by the multer middleware. This can lead to arbitrary file write and potentially remote code execution. The issue is fixed in version 0.7.6. | |
| Analizada | Alta (7.5) | 0.92% | — | Librechat | 20/3/2025 | 17/6/2026 | An unhandled exception in danny-avila/librechat version 3c94ff2 can lead to a server crash. The issue occurs when the fs module throws an exception while handling file uploads. An unauthenticated user can trigger this exception by sending a specially crafted request, causing the server to crash. The vulnerability is… | |
| Modificada | Media (5.3) | 0.55% | — | Librechat | 20/3/2025 | 17/6/2026 | An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue occurs because the endpoint does not verify whether the provided prompt ID belongs to the current user. | |
| Modificada | Media (6.5) | 0.73% | — | Gaizhenbiao Chuanhuchatgpt | 20/3/2025 | 17/6/2026 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in gaizhenbiao/chuanhuchatgpt, as of commit 20b2e02. The server uses the regex pattern `r'<[^>]+>'` to parse user input. In Python's default regex engine, this pattern can take polynomial time to match certain crafted inputs. An attacker can exploit… | |
| Analizada | Alta (7.5) | 0.62% | — | Lm-sys Fastchat | 20/3/2025 | 17/6/2026 | A Denial of Service (DoS) vulnerability exists in the file upload feature of lm-sys/fastchat version 0.2.36. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. An attacker can exploit this by sending a payload with an excessively large filename, causing the… | |
| Analizada | Media (6.1) | 0.78% | 💥 Exploit | Lm-sys Fastchat | 20/3/2025 | 17/6/2026 | An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft. | |
| Modificada | Alta (7.5) | 0.69% | — | Lm-sys Fastchat | 20/3/2025 | 17/6/2026 | In lm-sys/fastchat Release v0.2.36, the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploited by sending malformed multipart requests with arbitrary characters at the end of the boundary. Each extra character is processed in an infinite loop, leading to… | |
| Modificada | Media (6.5) | 0.73% | — | Gaizhenbiao Chuanhuchatgpt | 20/3/2025 | 17/6/2026 | gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion vulnerability due to the use of the gradio component gr.JSON, which has a known issue (CVE-2024-4941). This vulnerability allows unauthenticated users to access arbitrary files on the server by uploading a specially crafted JSON file… | |
| Modificada | Alta (7.5) | 0.71% | — | Gaizhenbiao Chuanhuchatgpt | 20/3/2025 | 17/6/2026 | An unauthenticated Denial of Service (DoS) vulnerability was identified in ChuanhuChatGPT version 20240918, which could be exploited by sending large data payloads using a multipart boundary. Although a patch was applied for CVE-2024-7807, the issue can still be exploited by sending data in groups with 10 characters… | |
| Modificada | Media (6.5) | 0.37% | — | Librechat | 20/3/2025 | 17/6/2026 | An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpoint does not verify whether the provided attachment ID belongs to the current user, allowing any authenticated user to delete attachments of other users. | |
| Modificada | Media (5.4) | 0.35% | — | Librechat | 20/3/2025 | 17/6/2026 | In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and create prompts without being granted permission by the admin. This can break application logic and permissions, allowing unauthorized actions. | |
| Modificada | Crítica (9.1) | 0.99% | — | Librechat | 20/3/2025 | 17/6/2026 | An arbitrary file deletion vulnerability exists in danny-avila/librechat version v0.7.5-rc2, specifically within the /api/files endpoint. This vulnerability arises from improper input validation, allowing path traversal techniques to delete arbitrary files on the server. Attackers can exploit this to bypass security… | |
| Analizada | Media (4.6) | 0.38% | — | Librechat | 20/3/2025 | 17/6/2026 | In danny-avila/librechat version v0.7.5-rc2, a vulnerability exists in the preset creation functionality where a user can manipulate the user ID field through mass assignment. This allows an attacker to inject a different user ID into the preset object, causing the preset to appear in the UI of another user. The… | |
| Analizada | Media (4.8) | 0.26% | — | Chatwoot | 20/3/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in chatwoot/chatwoot versions 3.0.0 to 3.5.1. This vulnerability allows an admin user to inject malicious JavaScript code via the dashboard app settings, which can then be executed by another admin user when they access the affected dashboard app. The issue is… | |
| Analizada | Media (5.3) | 0.56% | — | 274056675 Springboot-openai-chatgpt | 15/3/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in 274056675 springboot-openai-chatgpt e84f6f5. This affects the function deleteChat of the file /api/mjkj-chat/chat/ai/delete/chat of the component Chat History Handler. The manipulation of the argument chatListId leads to improper access controls. It is… | |
| Analizada | Media (5.3) | 0.48% | — | 274056675 Springboot-openai-chatgpt | 15/3/2025 | 17/6/2026 | A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5. It has been declared as problematic. This vulnerability affects the function updateQuestionCou of the file /api/mjkj-chat/chat/mng/update/questionCou of the component Number of Question Handler. The manipulation leads to enforcement of… | |
| Analizada | Media (6.9) | 0.70% | — | 274056675 Springboot-openai-chatgpt | 15/3/2025 | 17/6/2026 | A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5. It has been classified as critical. This affects an unknown part of the file /chatgpt-boot/src/main/java/org/springblade/modules/mjkj/controller/OpenController.java. The manipulation leads to hard-coded credentials. It is possible to initiate… | |
| Analizada | Media (5.3) | 0.44% | — | 274056675 Springboot-openai-chatgpt | 15/3/2025 | 17/6/2026 | A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by this issue is some unknown functionality of the file /api/mjkj-chat/cgform-api/addData/. The manipulation of the argument chatUserID leads to business logic errors. The attack may be launched remotely. The… | |
| Analizada | Media (6.9) | 0.71% | — | 274056675 Springboot-openai-chatgpt | 14/3/2025 | 17/6/2026 | A vulnerability has been found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by this vulnerability is the function submit of the file /api/blade-user/submit of the component User Handler. The manipulation leads to improper authorization. The attack can be launched remotely. The… | |
| Aplazada | Alta (7.1) | 0.15% | — | Hieu Nguyen Wati Chat AND NotificationAI | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Hieu Nguyen WATI Chat and Notification wati-chat-and-notification allows Stored XSS.This issue affects WATI Chat and Notification: from n/a through <= 1.1.2. | |
| Aplazada | Alta (7.1) | 0.39% | — | Mauricio Urrego Chatgpt Open AI Images & Content FOR WoocommerceAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mauricio Urrego ChatGPT Open AI Images & Content for WooCommerce glasses-for-woocommerce allows Reflected XSS.This issue affects ChatGPT Open AI Images & Content for WooCommerce: from n/a through <= 2.2.0. | |
| Analizada | Media (5.4) | 0.27% | — | Premio Floating Chat Widget | 27/2/2025 | 17/6/2026 | The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-hover’ parameter in all versions up to, and including, 3.3.5 due to insufficient input sanitization and output… | |
| Aplazada | Alta (7.5) | 0.77% | — | Quantumcloud ChatbotAI | 25/2/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in QuantumCloud ChatBot chatbot allows PHP Local File Inclusion.This issue affects ChatBot: from n/a through <= 6.3.5. | |
| Aplazada | Crítica (10) | 0.63% | — | Premio Chaty PROAI | 22/2/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Chaty Pro allows Upload a Web Shell to a Web Server. This issue affects Chaty Pro: from n/a through 3.3.3. | |
| Analizada | Baja (3.8) | 0.29% | — | Angeljudesuarez Simple Chatbox | 21/2/2025 | 17/6/2026 | A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /del.php. The attack can use SQL injection to obtain sensitive data. |