Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.50% | — | Gaizhenbiao Chuanhuchatgpt | 6/6/2024 | 17/6/2026 | In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper access control mechanisms. This flaw allows an authenticated attacker to bypass intended access restrictions and read the `history` files of other users, potentially leading to unauthorized access… | |
| Modificada | Media (5.4) | 0.46% | — | Gaizhenbiao Chuanhuchatgpt | 6/6/2024 | 17/6/2026 | A stored Cross-Site Scripting (XSS) vulnerability existed in version (20240121) of gaizhenbiao/chuanhuchatgpt due to inadequate sanitization and validation of model output data. Despite user-input validation efforts, the application fails to properly sanitize or validate the output from the model, allowing for the… | |
| Modificada | Crítica (9.8) | 3.8% | 💥 Exploit | Gaizhenbiao Chuanhuchatgpt | 6/6/2024 | 17/6/2026 | The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdated gradio component. The application is designed to restrict user access to resources within the `web_assets` folder. However, the outdated version of gradio it employs is susceptible to path traversal, as… | |
| Modificada | Alta (7.5) | 0.52% | — | Gaizhenbiao Chuanhuchatgpt | 4/6/2024 | 17/6/2026 | An improper access control vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically in version 20240410. This vulnerability allows any user on the server to access the chat history of any other user without requiring any form of interaction between the users. Exploitation of this vulnerability… | |
| Analizada | Alta (7.5) | 0.60% | — | Gaizhenbiao Chuanhuchatgpt | 16/5/2024 | 17/6/2026 | A Local File Inclusion (LFI) vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically within the functionality for uploading chat history. The vulnerability arises due to improper input validation when handling file paths during the chat history upload process. An attacker can exploit this… | |
| Analizada | Alta (7.5) | 0.78% | — | Gaizhenbiao Chuanhuchatgpt | 10/4/2024 | 17/6/2026 | gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` file. This vulnerability is present in both authenticated and unauthenticated versions of the application, enabling attackers to obtain sensitive information such as API keys (`openai_api_key`,… | |
| Modificada | Media (5.3) | 0.62% | — | Chuanhuchatgpt Project Chuanhuchatgpt | 2/6/2023 | 17/6/2026 | ChuanhuChatGPT is a graphical user interface for ChatGPT and many large language models. A vulnerability in versions 20230526 and prior allows unauthorized access to the config.json file of the privately deployed ChuanghuChatGPT project, when authentication is not configured. The attacker can exploit this… |