Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.30% | — | Gingerplugins Sticky Chat WidgetAI | 11/9/2026 | 11/9/2026 | The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This is due to the save_form_data() function passing attacker-controlled POST array keys unsanitized to… | |
| Aplazada | Alta (8.1) | 0.44% | — | Wise ChatAI | 10/9/2026 | 6/10/2026 | Deserialization of Untrusted Data vulnerability in Marcin Wise Chat wise-chat allows Object Injection.This issue affects Wise Chat: from n/a through 3.4.2. | |
| Aplazada | Crítica (9.4) | 0.49% | — | SQL ChatAI | 5/9/2026 | 24/9/2026 | SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to internal databases, execute SQL commands, enumerate schemas, and pivot into the server's network without… | |
| Aplazada | Media (6.4) | 0.20% | — | Social Chat Click TO Chat APP ButtonAI | 5/9/2026 | 8/9/2026 | The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box in all versions up to, and including, 8.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.3) | 0.72% | — | Lmsys FastchatAI | 4/9/2026 | 10/9/2026 | FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious workers under victim model names to intercept user prompts, images, and… | |
| Aplazada | Alta (8.5) | 0.25% | — | Aider-chatAI | 4/9/2026 | 10/9/2026 | aider (aider-chat) automatically loads a .aider.conf.yml configuration file from the root of the git repository it is launched in. A crafted repository can set test-cmd (executed at startup) or lint-cmd (executed on the first file edit), which aider runs through a shell (subprocess with shell=True) without any user… | |
| Aplazada | Alta (7.1) | 0.44% | — | Chatbot UIAISupabaseAI | 4/9/2026 | 24/9/2026 | Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers to access private file content belonging to other users by supplying arbitrary file UUIDs. The endpoint uses a service-role Supabase client that bypasses row-level security and fails to validate file… | |
| Aplazada | Media (6.9) | 0.20% | — | Lobehub LobechatAI | 4/9/2026 | 24/9/2026 | LobeChat (LobeHub) 2.2.1 does not properly verify inbound chat-platform webhook signatures in the QQ and Feishu adapters. The webhook route (/api/agent/webhooks/:platform) is unauthenticated by design and delegates verification to each adapter; the QQ adapter performs no Ed25519 signature verification on dispatched… | |
| Aplazada | Media (5.5) | 0.64% | — | Sigoden AichatAI | 2/9/2026 | 28/9/2026 | A flaw has been found in sigoden aichat up to 0.30.4. This affects an unknown function of the file src/serve.rs of the component API Endpoint. This manipulation causes uncontrolled memory allocation. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early… | |
| Aplazada | Alta (8.8) | 0.51% | — | Plugin-planet Simple Ajax ChatAI | 2/9/2026 | 3/9/2026 | The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inject arbitrary HTML attributes into the page and run scripts in the browser of anyone viewing the chat, including administrators. | |
| Aplazada | Media (5.3) | 0.32% | — | Zhongyu09 OpenchatbiAI | 1/9/2026 | 1/9/2026 | A security flaw has been discovered in zhongyu09 OpenChatBI up to 0.3.0. Affected by this vulnerability is the function _validate_sql_safety of the file openchatbi/text2sql/generate_sql.py. Performing a manipulation results in sql injection. The attack can be initiated remotely. Versions v0.2.0 through v0.2.2 have no… | |
| Aplazada | Baja (2.9) | 0.57% | — | Sdcb ChatsAI | 31/8/2026 | 1/9/2026 | A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the file src/BE/web/Controllers/Chats/Files/FileController.cs of the component Signed File Download Endpoint. This manipulation causes missing authentication. Remote exploitation of the attack is possible. The attack's… | |
| Aplazada | Baja (2.1) | 0.38% | — | Sdcb ChatsAI | 31/8/2026 | 31/8/2026 | A vulnerability was detected in sdcb chats up to 1.12.0. This affects the function McpController of the file src/BE/web/Controllers/Users/Mcps/McpController.cs of the component fetch-tools Endpoint. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public… | |
| Aplazada | Alta (8.7) | 0.51% | — | NextchatAI | 30/8/2026 | 10/9/2026 | NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching instead of hostname parsing, allowing any URL containing 'api.openai.com' to pass… | |
| Aplazada | Media (6.5) | 0.40% | — | Bitcollider Bitchat IOSAI | 28/8/2026 | 1/9/2026 | An issue in BitChat for iOS v1.15.0 allows a remote attacker to cause a denial of service via an unauthenticated MESSAGE packet into the mesh gossip cache | |
| En análisis | Media (6.5) | 0.27% | — | Synology Chat ServerAI | 28/8/2026 | 1/9/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write restricted files and conduct limited denial-of-service attacks in DSM. | |
| En análisis | Media (4.3) | 0.36% | — | Synology Chat ServerAI | 28/8/2026 | 1/9/2026 | A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote authenticated users to obtain non-sensitive information. | |
| En análisis | Crítica (9) | 0.49% | — | Synology Chat ServerAI | 28/8/2026 | 1/9/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSM. | |
| Aplazada | Crítica (9.8) | 1.1% | — | Simplex ChatAI | 26/8/2026 | 9/9/2026 | A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via sending a crafted payload in a text message. | |
| Pendiente de análisis | Media (6.9) | 0.40% | — | Rocket.chatAI | 25/8/2026 | 10/9/2026 | Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauthenticated caller may invoke it as often as it likes. The method is reachable over DDP and over the HTTP route POST /api/v1/method.callAnon/sendForgotPasswordEmail, and it triggers a password reset message for any… | |
| Aplazada | Alta (7.5) | 0.42% | — | Siteleads Lead Generation Contact Widget AND AI ChatbotAI | 24/8/2026 | 26/8/2026 | Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions. | |
| Aplazada | Media (6.1) | 0.28% | — | Nopaperforms Niaa-chatbotAI | 24/8/2026 | 9/9/2026 | A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows remote attackers to inject arbitrary web script or HTML via the Enter email parameter. | |
| Aplazada | Alta (8.7) | 0.45% | — | RansomlookAIRocket.chatAIBlueskyAIJoinmastodon MastodonAI+1 | 24/8/2026 | 26/8/2026 | RansomLook fails to enforce the privacy status of ransomware groups and markets when distributing newly collected victim posts to external notification channels. The post-processing logic checks whether an individual post is marked private but does not verify whether the group or market to which the post belongs is… | |
| Aplazada | Alta (7.4) | 0.43% | — | WeechatAI | 21/8/2026 | 9/9/2026 | WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker can exploit timing differences to… | |
| Aplazada | Media (6.5) | 0.48% | — | WeechatAI | 21/8/2026 | 9/9/2026 | WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay module's WebSocket permessage-deflate decompression function relay_websocket_inflate() has no upper bound on output size. An authenticated relay user can send a small compressed WebSocket frame (~100… |