Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

106 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)1.7%—Danswer-ai DanswerAI20/3/202517/6/2026
An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files. The application does not verify whether the attacker is the creator of the file, allowing the attacker to directly call the GET /api/chat/file/{file_id} interface to view any user's file.
AplazadaAlta (8.1)0.21%—Danswer-ai DanswerAI20/3/202517/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability in version v1.4.1 of danswer-ai/danswer allows attackers to perform unauthorized actions in the context of the victim's browser. This includes connecting the victim's application with a malicious Slack Bot, inviting users, and deleting chats, among other actions. The…
AplazadaMedia (4.3)0.41%—Danswer-ai DanswerAI20/3/202517/6/2026
In version 0.4.1 of danswer-ai/danswer, a vulnerability exists where a basic user can create credentials and link them to an existing connector. This issue arises because the system allows an unauthenticated attacker to sign up with a basic account and perform actions that should be restricted to admin users. This can…
AplazadaAlta (7.5)0.52%—Danswer-ai DanswerAI20/3/202517/6/2026
A vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to cause a Denial of Service (DoS) by uploading a file with a malformed multipart boundary. By appending a large number of characters to the end of the multipart boundary, the server continuously processes each character, rendering the application…
AplazadaCrítica (9.1)0.93%—Danswer-ai DanswerAI20/3/202517/6/2026
An arbitrary file overwrite vulnerability exists in the ZulipConnector of danswer-ai/danswer, affecting the latest version. The vulnerability arises from the load_credentials method, where user-controlled input for realm_name and zuliprc_content is used to construct file paths and write file contents. This allows…
AplazadaAlta (7.4)0.28%—Danswer-ai DanswerAI20/3/202517/6/2026
A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows attackers to steal sensitive information such as chat contents, API keys, and other data. This vulnerability occurs due to improper validation of the origin header, enabling malicious web pages to make unauthorized requests to the application's API.
AplazadaAlta (7.5)0.70%—Danswer-ai DanswerAI20/3/202517/6/2026
A vulnerability in danswer-ai/danswer version 1 allows an attacker to perform a Regular Expression Denial of Service (ReDoS) by manipulating regular expressions. This can significantly slow down the application's response time and potentially render it completely unusable.
AplazadaMedia (4.3)0.44%—Cminds CM AnswersAI13/12/202417/6/2026
Missing Authorization vulnerability in CreativeMindsSolutions CM Answers cm-answers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CM Answers: from n/a through <= 3.2.6.
AplazadaMedia (6.4)0.29%—FAQ AND AnswersAI12/12/202417/6/2026
The FAQ And Answers – Create Frequently Asked Questions Area on WP Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'faq' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
AplazadaAlta (7.5)0.39%—Mistergroup ShouldianswerAI4/12/202417/6/2026
The Mister org.mistergroup.shouldianswer application 1.4.264 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the org.mistergroup.shouldianswer.ui.default_dialer.DefaultDialerActivity component.
AnalizadaBaja (2.6)0.25%—Apache Answer22/11/202417/6/2026
Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.0. The ids generated using the UUID v1 version are to some extent not secure enough. It can cause the generated token to be predictable. Users are recommended to upgrade to version 1.4.1, which fixes the issue.
AnalizadaMedia (5.3)0.75%—Apache Answer25/9/202417/6/2026
Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. Using the MD5 value of a user's email to access Gravatar is insecure and can lead to the leakage of user email. The official recommendation is to use SHA256 instead. Users are recommended to upgrade to…
ModificadaMedia (5.3)1.1%—Apache Answer12/8/202417/6/2026
Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. User sends multiple password reset emails, each containing a valid link. Within the link's validity period, this could potentially lead to the link being misused or hijacked. Users are…
ModificadaMedia (5.3)1.2%—Apache Answer12/8/202417/6/2026
Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. The password reset link remains valid within its expiration period even after it has been used. This could potentially lead to the link being misused or hijacked. Users are recommended…
AplazadaCrítica (9.8)0.80%—DanswerAI26/4/202417/6/2026
Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access to GET/SET of Slack Bot Tokens. Anyone with network access can steal slack bot tokens and set them. This implies full compromise of the customer's slack bot, leading to internal Slack access. This…
AnalizadaMedia (4.6)0.97%—Apache Answer21/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0. XSS attack when user changes personal website. A logged-in user, when modifying their personal website, can input malicious code in the website to create…
ModificadaMedia (5.9)0.90%—Apache Answer22/2/202417/6/2026
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Repeated submission during registration resulted in the registration of the same user. When users register, if they rapidly submit multiple…
ModificadaMedia (5.4)1.1%—Apache Answer22/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. XSS attack when user enters summary. A logged-in user, when modifying their own submitted question, can input malicious code in the summary to create such…
AnalizadaCrítica (9.1)2.5%—Apache Answer22/2/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an attack by uploading an image when posting content. Users are recommended…
ModificadaBaja (3.1)0.89%—Apache Answer10/1/202417/6/2026
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer. This issue affects Apache Answer: through 1.2.0. Under normal circumstances, a user can only bookmark a question once, and will only increase the number of questions bookmarked once. However,…
ModificadaAlta (8.8)0.82%—Answer7/9/202317/6/2026
Missing Authentication for Critical Function in GitHub repository answerdev/answer prior to v1.1.3.
ModificadaMedia (5.9)0.48%—Answer3/8/202317/6/2026
Race Condition within a Thread in GitHub repository answerdev/answer prior to v1.1.1.
ModificadaAlta (8.8)0.57%—Answer3/8/202317/6/2026
Insufficient Session Expiration in GitHub repository answerdev/answer prior to v1.1.0.
ModificadaAlta (8.8)0.88%—Answer3/8/202317/6/2026
Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0.
ModificadaMedia (6.5)0.65%—Answer3/8/202317/6/2026
Missing Authorization in GitHub repository answerdev/answer prior to v1.1.1.