Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
1144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.64% | — | Projectworlds Simple Web-based Chat Application | 28/10/2024 | 17/6/2026 | A vulnerability has been found in Project Worlds Simple Web-Based Chat Application 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Aplazada | Media (6.1) | 0.34% | — | Aiml ChatbotAI | 25/10/2024 | 17/6/2026 | AIML Chatbot 1.0 (fixed in 2.0) is vulnerable to Cross Site Scripting (XSS). The vulnerability is exploited through the message input field, where attackers can inject malicious HTML or JavaScript code. The chatbot fails to sanitize these inputs, leading to the execution of malicious scripts. | |
| Modificada | Media (5.3) | 0.27% | — | 10web WPS Telegram Chat | 25/10/2024 | 17/6/2026 | The WPS Telegram Chat plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when accessing messages in versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to view the messages that are sent through the Telegram Bot API. | |
| Modificada | Media (6.5) | 0.27% | — | 10web WPS Telegram Chat | 25/10/2024 | 17/6/2026 | The WPS Telegram Chat plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'Wps_Telegram_Chat_Admin::checkСonnection' function in versions up to, and including, 4.6.0. This makes it possible for authenticated attackers, with subscriber-level… | |
| Aplazada | Crítica (9.1) | 0.56% | — | Netangular Technologies Chatnet AIAI | 24/10/2024 | 17/6/2026 | A prompt injection vulnerability in the chatbox of Netangular Technologies ChatNet AI Version v1.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message. | |
| Aplazada | Crítica (9.1) | 0.56% | — | Fusion Chat Chat AI Assistant ASK ME AnythingAI | 24/10/2024 | 17/6/2026 | A prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message. | |
| Aplazada | Alta (7.5) | 0.42% | — | Butterfly Effect Limited Monica Chatgpt AI AssistantAI | 24/10/2024 | 17/6/2026 | A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message. | |
| Modificada | Media (6.1) | 0.17% | — | Avchat.net Avchat Video Chat | 20/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Stefan Nour AVChat Video Chat avchat-3 allows Stored XSS.This issue affects AVChat Video Chat: from n/a through <= 2.2. | |
| Modificada | Media (5.4) | 0.33% | — | Ninjateam Click TO Chat | 18/10/2024 | 17/6/2026 | The Click to Chat – WP Support All-in-One Floating Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsaio_snapchat shortcode in all versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Modificada | Media (5.4) | 0.55% | — | Ninjateam Click TO Chat | 17/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Ninja Team Click to Chat – WP Support All-in-One Floating Widget support-chat allows Stored XSS.This issue affects Click to Chat – WP Support All-in-One Floating Widget: from n/a through <= 2.3.3. | |
| Aplazada | Alta (7.4) | 0.35% | — | Facebook Chat PluginAI | 16/10/2024 | 17/6/2026 | The Facebook Chat Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_update_options function in versions up to, and including, 1.5. This flaw makes it possible for low-level authenticated attackers to connect their own Facebook Messenger account to any site… | |
| Aplazada | Media (6.7) | 0.55% | — | Rocket.chat MobileAI | 7/10/2024 | 17/6/2026 | The E2EE password entropy generated by Rocket.Chat Mobile prior to version 4.5.1 is insufficient, allowing attackers to crack it if they have the appropriate time and resources. | |
| Aplazada | Alta (7.5) | 0.56% | — | Istmoplugins Instant-chat-floating-button-for-wordpress-websitesAI | 5/10/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in istmoplugins Instant Chat Floating Button for WordPress Websites instant-chat-wp allows PHP Local File Inclusion.This issue affects Instant Chat Floating Button for WordPress Websites: from n/a through <= 1.0.5. | |
| Aplazada | Crítica (9.8) | 0.85% | — | Wechat Social LoginAI | 1/10/2024 | 17/6/2026 | The Wechat Social login plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'convert_remoteimage_to_local' function in versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's… | |
| Aplazada | Crítica (9.8) | 1.7% | 💥 PoC | Wechat Social LoginAI | 1/10/2024 | 17/6/2026 | The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0. This is due to insufficient verification on the user being supplied during the social login. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such… | |
| Aplazada | Media (6.4) | 0.34% | — | Rumbletalk Live Group ChatAI | 1/10/2024 | 17/6/2026 | The RumbleTalk Live Group Chat – HTML5 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rumbletalk-admin-button' shortcode in all versions up to, and including, 6.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Alta (7.2) | 0.36% | — | 123chatAI | 1/10/2024 | 17/6/2026 | The 123.chat - Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a… | |
| Analizada | Alta (7.5) | 0.85% | 💥 Exploit | Ays-pro Chatgpt Assistant | 27/9/2024 | 17/6/2026 | The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and… | |
| Modificada | Alta (7.5) | 0.30% | — | Ays-pro Chatgpt Assistant | 27/9/2024 | 17/6/2026 | The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users to obtain it | |
| Analizada | Media (5.3) | 1.1% | 💥 Exploit | Webdigit Chatbot With Chatgpt | 25/9/2024 | 17/6/2026 | The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, thereby leaking the OpenAI API key | |
| Modificada | Media (5.4) | 0.35% | — | Rocket.chat | 25/9/2024 | 17/6/2026 | Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier allows stored XSS in the description and release notes of the marketplace and private apps. | |
| Aplazada | Alta (7.5) | 0.41% | — | Rocket.chatAI | 25/9/2024 | 17/6/2026 | Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and before is vulnerable to a message forgery / impersonation issue. Attackers can abuse the UpdateOTRAck method to send ephemeral messages as if they were any other user they choose. | |
| Modificada | Alta (7.5) | 0.59% | — | Rocket.chat | 25/9/2024 | 17/6/2026 | Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash the workspace due to an issue in the message parser. | |
| Modificada | Media (6.1) | 0.33% | — | Rocket.chat | 25/9/2024 | 17/6/2026 | Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XSS). Attackers may be able to abuse the UpdateOTRAck method to forge a message that contains an XSS payload. | |
| Analizada | Alta (8.8) | 12% | 💥 PoC | Lobehub Lobe Chat | 23/9/2024 | 17/6/2026 | Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` does not consider redirect and could be bypassed when attacker provides an external malicious URL which redirects to internal resources like a… |