Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
233 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.9) | 0.44% | — | Mailmint Mail MintAI | 9/7/2026 | 9/7/2026 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to time-based SQL Injection via the 'contact_ids' parameter in all versions up to, and including, 1.24.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation… | |
| Aplazada | Alta (8.7) | 0.55% | — | Elixir-mint HpaxAI | 6/7/2026 | 6/7/2026 | Inefficient Algorithmic Complexity vulnerability in elixir-mint hpax allows unauthenticated denial-of-service via unbounded HPACK integer decoding. hpax decodes HPACK variable-length integers with no upper bound on the decoded value or the number of continuation octets. 'Elixir.HPAX.Types':decode_remaining_integer/3… | |
| Aplazada | Alta (8.7) | 0.52% | — | Elixir-mint MintAI | 6/7/2026 | 6/7/2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint (Mint.HTTP1 module) allows a denial of service via an oversized chunked transfer-encoded response. This vulnerability is associated with program files lib/mint/http1.ex and program routines 'Elixir.Mint.HTTP1':decode_body/5,… | |
| Aplazada | Alta (8.1) | 0.37% | — | Advancedformintegration Advanced Form IntegrationAI | 1/7/2026 | 1/7/2026 | The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress role assigned when it creates a user from a public form submission, allowing unauthenticated visitors to create an administrator account when an active integration maps the user role to a public… | |
| Aplazada | Ninguna (0) | 0.40% | — | Mintplexlabs AnythingllmAI | 24/6/2026 | 25/6/2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.11.1 until 1.14.1, userId/workspaceId scoping to the parsed-files read/delete paths was added. However, the POST /api/workspace/:slug/embed-parsed-file/:fileId flow still deletes the… | |
| Aplazada | Media (4.3) | 0.34% | — | Mintplexlabs AnythingllmAI | 24/6/2026 | 25/6/2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, on Windows, the document folder listing route can accept an encoded absolute Windows path that resolves outside the intended documents directory. The shared path containment… | |
| Aplazada | Media (6.5) | 0.30% | — | Advancedformintegration Advanced Form IntegrationAI | 15/6/2026 | 17/6/2026 | Subscriber Broken Access Control in Advanced Form Integration <= 1.126.12 versions. | |
| Aplazada | Alta (8.2) | 0.52% | — | Elixir-mint MintAI | 2/6/2026 | 22/7/2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 servers to exhaust memory in a Mint client (HTTP/2 CONTINUATION flood). When Mint's HTTP/2 receive path observes a HEADERS frame without the END_HEADERS flag, the unparsed header-block fragment is… | |
| Aplazada | Media (6.3) | 0.52% | — | Elixir MintAI | 2/6/2026 | 22/7/2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint Mint allows attacker-controlled HTTP/1 servers to desynchronise response framing on shared connections. Mint's HTTP/1 Content-Length parser, Mint.HTTP1.Parse.content_length_header/1 in lib/mint/http1/parse.ex,… | |
| Aplazada | Alta (8.2) | 0.52% | — | Elixir-mint MintAI | 2/6/2026 | 22/7/2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 servers to exhaust memory in a Mint client via PUSH_PROMISE flooding. In lib/mint/http2.ex, Mint.HTTP2.decode_push_promise_headers_and_add_response/5 inserts a :reserved_remote entry into… | |
| Aplazada | Baja (2.1) | 0.22% | — | Elixir-mint MintAI | 2/6/2026 | 22/7/2026 | Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in elixir-mint Mint allows HTTP Request Splitting and HTTP Request Smuggling. In lib/mint/http1/request.ex, the encode_request_line/2 function splices the caller-supplied method and target arguments directly into the HTTP/1 request line without… | |
| Modificada | Alta (8.8) | 0.54% | — | Mintplexlabs Anythingllm | 28/5/2026 | 21/7/2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the filesystem-search-files agent skill passes its LLM-controlled pattern parameter to ripgrep as a positional argument without a -- end-of-options separator. ripgrep parses any… | |
| Analizada | Media (4.3) | 0.30% | — | Mintplexlabs Anythingllm | 28/5/2026 | 21/7/2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, an approved mobile device token created in single-user mode can survive single-user -> multi-user migration even when the device record has userId = null. In multi-user mode,… | |
| Analizada | Baja (2.5) | 0.23% | — | Mintplexlabs Anythingllm | 28/5/2026 | 21/7/2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the AnythingLLM agent filesystem copy tool validates only the top-level source and destination paths. The recursive copy helper then descends into child entries using fs.stat()… | |
| Aplazada | Media (4.3) | 0.29% | — | Mail MintAI | 21/5/2026 | 23/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPFunnels Team Mail Mint allows Retrieve Embedded Sensitive Data. This issue affects Mail Mint: from n/a through 1.19.5. | |
| Analizada | Media (4.3) | 0.34% | — | Mintplexlabs Anythingllm | 8/5/2026 | 24/7/2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.12.1, GET /api/workspace/:slug/tts/:chatId in AnythingLLM returns the text-to-speech audio for another user's chat response within the same workspace because the route… | |
| Analizada | Media (5.4) | 0.27% | — | Mintplexlabs Anythingllm | 24/4/2026 | 17/6/2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.12.1, AnythingLLM's in-chat markdown renderer has an unsafe custom rule for images that interpolates the markdown image's `alt` text into an HTML `alt="..."` attribute without… | |
| Analizada | Alta (7.2) | 1.1% | — | Mintplexlabs Anythingllm | 7/4/2026 | 17/6/2026 | A path traversal vulnerability exists in mintplex-labs/anything-llm versions up to and including 1.9.1, within the `AgentFlows` component. The vulnerability arises from improper handling of user input in the `loadFlow` and `deleteFlow` methods in `server/utils/agentFlows/index.js`. Specifically, the combination of… | |
| Analizada | Media (6.4) | 0.52% | — | Mintplexlabs Anythingllm | 16/3/2026 | 17/6/2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The ImportedPlugin.importCommunityItemFromUrl() function in server/utils/agents/imported.js downloads a ZIP file from a community hub URL and extracts it using… | |
| Analizada | Baja (2.7) | 0.33% | — | Mintplexlabs Anythingllm | 16/3/2026 | 17/6/2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, in multi-user mode, AnythingLLM blocks suspended users on the normal JWT-backed session path, but it does not block them on the browser extension API key path. If a user… | |
| Analizada | Baja (3.8) | 0.27% | — | Mintplexlabs Anythingllm | 16/3/2026 | 17/6/2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The two generic system-preferences endpoints allow manager role access, while every other surface that touches the same settings is restricted to admin only. Because of… | |
| Analizada | Alta (7.7) | 0.45% | — | Mintplexlabs Anythingllm | 16/3/2026 | 17/6/2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, a SQL injection vulnerability in the built-in SQL Agent plugin allows any user who can invoke the agent to execute arbitrary SQL commands on connected databases. The… | |
| Analizada | Crítica (9.6) | 0.73% | — | Mintplexlabs Anythingllm | 16/3/2026 | 17/6/2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, AnythingLLM Desktop contains a Streaming Phase XSS vulnerability in the chat rendering pipeline that escalates to Remote Code Execution on the host OS due to insecure… | |
| Analizada | Alta (7.5) | 0.40% | — | Mintplexlabs Anythingllm | 16/3/2026 | 17/6/2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, On default installations where no password or API key has been configured, all HTTP endpoints and the agent WebSocket lack authentication, and the server's CORS policy… | |
| Aplazada | Alta (7.5) | 1.5% | — | Mail MintAI | 4/3/2026 | 17/6/2026 | The Mail Mint WordPress plugin before 1.19.5 does not have authorization in one of its REST API endpoint, allowing unauthenticated users to call it and retrieve the email addresses of users on the blog |